Описание
Security update for shadow
This update for shadow fixes the following issues:
- CVE-2016-6252: Incorrect integer handling could results in local privilege escalation (bsc#1099310)
Список пакетов
SUSE Enterprise Storage 4
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Desktop 12 SP3
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP2-LTSS
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP3
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
shadow-4.2.1-27.9.1
SUSE OpenStack Cloud 7
shadow-4.2.1-27.9.1
Ссылки
- Link for SUSE-SU-2018:1997-1
- E-Mail link for SUSE-SU-2018:1997-1
- SUSE Security Ratings
- SUSE Bug 1099310
- SUSE CVE CVE-2016-6252 page
Описание
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
Затронутые продукты
SUSE Enterprise Storage 4:shadow-4.2.1-27.9.1
SUSE Linux Enterprise Desktop 12 SP3:shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP2-LTSS:shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP3:shadow-4.2.1-27.9.1
Ссылки
- CVE-2016-6252
- SUSE Bug 1099310
- SUSE Bug 979282