Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:1997-1

Опубликовано: 19 июл. 2018
Источник: suse-cvrf

Описание

Security update for shadow

This update for shadow fixes the following issues:

  • CVE-2016-6252: Incorrect integer handling could results in local privilege escalation (bsc#1099310)

Список пакетов

SUSE Enterprise Storage 4
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Desktop 12 SP3
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP2-LTSS
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP3
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
shadow-4.2.1-27.9.1
SUSE OpenStack Cloud 7
shadow-4.2.1-27.9.1

Описание

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.


Затронутые продукты
SUSE Enterprise Storage 4:shadow-4.2.1-27.9.1
SUSE Linux Enterprise Desktop 12 SP3:shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP2-LTSS:shadow-4.2.1-27.9.1
SUSE Linux Enterprise Server 12 SP3:shadow-4.2.1-27.9.1

Ссылки