Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Slackware 13.1 Shadow Security Update: Denial Of Service Issue

slackware
Calendar Grey April 11, 2011
Dist Slackware Esm H88
Update bundles for Slackware 13.1 address a vulnerability related to permissions that may lead to service disruption.
New shadow packages are available for Slackware 13.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 13.1 ChangeLog: patches/packages/shadow-4.1.4.3-i486-2_slack13.1.txz: Rebuilt. Corrected a packaging error where incorrect permissions on /usr/sbin/lastlog and /usr/sbin/faillog allow any user to set login failure limits on any other user (including root), potentially leading to a denial of service. Thanks to pyllyukko for discovering and reporting this vulnerability. (* Security fix *) Where to find the new package: HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware

Read the Full Advisory

Where Find New Packages

MD5 Signatures

Slackware 13.1 package: 6af48ee8f22b4c429d8d12b45600c440 shadow-4.1.4.3-i486-2_slack13.1.txz
Slackware x86_64 13.1 package: 627d993c084ba4ad541d23c31e8507cc shadow-4.1.4.3-x86_64-2_slack13.1.txz
Slackware -current package: 522bb5ec7234e0a06c5f805e349a65c0 a/shadow-4.1.4.3-i486-2.txz
Slackware x86_64 -current package: 5eeb1ce5410ba3b721525ca90c669e1d a/shadow-4.1.4.3-x86_64-2.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg shadow-4.1.4.3-i486-2_slack13.1.txz

Related News

Your message here