Alerts This Week
Warning Icon 1 1,153
Alerts This Week
Warning Icon 1 1,153

Ubuntu 23.10 USN-6640-1 Critical: Shadow Sensitive Data Leak

ubuntu
Calendar Grey February 15, 2024
Dist Ubuntu Esm H88
The Ubuntu Security Notice USN-6640-1 pertains to a flaw in shadow that may lead to the unintended disclosure of confidential data.
shadow could be made to expose sensitive information.

Summary

shadow could be made to expose sensitive information.

Software Description:

- shadow: system login tools

Details:

It was discovered that shadow was not properly sanitizing memory when

running the password utility. An attacker could possibly use this issue

to retrieve a password from memory, exposing sensitive information.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
libsubid-dev 1:4.13+dfsg1-1ubuntu1.1
libsubid4 1:4.13+dfsg1-1ubuntu1.1
login 1:4.13+dfsg1-1ubuntu1.1
passwd 1:4.13+dfsg1-1ubuntu1.1
uidmap 1:4.13+dfsg1-1ubuntu1.1

Ubuntu 22.04 LTS:
login 1:4.8.1-2ubuntu2.2
passwd 1:4.8.1-2ubuntu2.2
uidmap 1:4.8.1-2ubuntu2.2

Ubuntu 20.04 LTS:
login 1:4.8.1-1ubuntu5.20.04.5
passwd 1:4.8.1-1ubuntu5.20.04.5
uidmap 1:4.8.1-1ubuntu5.20.04.5

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
login 1:4.5-1ubuntu2.5+esm1
passwd 1:4.5-1ubuntu2.5+esm1
uidmap 1:4.5-1ubuntu2.5+esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
login 1:4.2-3.1ubuntu5.5+esm4
passwd 1:4.2-3.1ubuntu5.5+esm4
uidmap 1:4.2-3.1ubuntu5.5+esm4

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
login 1:4.1.5.1-1ubuntu9.5+esm4
passwd 1:4.1.5.1-1ubuntu9.5+esm4
uidmap 1:4.1.5.1-1ubuntu9.5+esm4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6640-1

CVE-2023-4641

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6640-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here