Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 22: FEDORA-2015-12301 Critical: Libuser DoS Threat

fedora
Calendar Grey July 30, 2015
Dist Fedora Esm H88
Important patch release for libuser in Fedora 22 tackling significant vulnerabilities and improving user account protection.
Security fix for CVE-2015-3245, CVE-2015-3246

Summary

The libuser library implements a standardized interface for manipulating

and administering user and group accounts. The library uses pluggable

back-ends to interface to its data sources.

Sample applications modeled after those included with the shadow password

suite are included.

Update Information:

Security fix for CVE-2015-3245, CVE-2015-3246

Change Log

* Thu Jul 23 2015 Miloslav Trmač - 0.62-1 - Update to libuser-0.62 Resolves: #1246225 (CVE-2015-3245, CVE-2015-3246) * Wed Jun 17 2015 Fedora Release Engineering - 0.61-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Wed Mar 25 2015 Miloslav Trmač - 0.61-1 - Update to libuser-0.61, notably adding Python 3 bindings Resolves: #1014555 - Filter out libuser plugin and Python extension Provides: * Sat Feb 21 2015 Till Maas - 0.60-7 - Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code

References


[ 1 ] Bug #1233043 - CVE-2015-3245 libuser does not filter newline characters in the GECOS field https://bugzilla.redhat.com/show_bug.cgi?id=1233043 [ 2 ] Bug #1233052 - CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file https://bugzilla.redhat.com/show_bug.cgi?id=1233052

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update libuser' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libuser
Product: Fedora 22
Version: 0.62
Release: 1.fc22
Summary: A user and group account administration library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here