This update is merely a rebuild of the usermode package, which are a set of graphical tools for certain user account management tasks, fixing two issues: . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2744-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta August 16, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : usermode Version : 1.109-1+deb9u1 Debian Bug : 991808 This update is merely a rebuild of the usermode package, which are a set of graphical tools for certain user account management tasks, fixing two issues: a) the versioning issue as wheezy (Debian 7) had a greater version than jessie (Debian 8) and stretch (Debian 9), thereby causing upgrade issues. b) the package now Depends and Build-Depends on the newer libuser1-dev (> = 1:0.62~dfsg-0.1) to ensure the latest version of libuser is used (which was a security fix). For Debian 9 stretch, this problem has been fixed in version 1.109-1+deb9u1. We recommend that you upgrade your usermode packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-1234-1 deals with vulnerabilities in package management utilities affecting system usability during upgrades.. Debian LTS, Usermode Package, Upgrade Fix, Security Update, Graphical Account Tools. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for pam-modules ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1760-1 Rating: moderate References: #707645 Cross-References: CVE-2011-3172 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pam-modules fixes the following security issue: - CVE-2011-3172: Ensure that unix2_chkpwd calls pam_acct_mgmt to prevent usage of locked accounts (bsc#707645). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-pam-modules-13665=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-pam-modules-13665=1 Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): pam-modules-11-1.27.3.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): pam-modules-32bit-11-1.27.3.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): pam-modules-x86-11-1.27.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): pam-modules-debuginfo-11-1.27.3.1 pam-modules-debugsource-11-1.27.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (ppc64 s390x x86_64): pam-modules-debuginfo-32bit-11-1.27.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (ia64): pam-modules-debuginfo-x86-11-1.27.3.1 References: https://www.suse.com/security/cve/CVE-2011-3172.html https://bugzilla.suse.com/707645 . SUSE Security Advisory forlibxml2 (ID: SUSE-SU-2018:1770-1) addresses moderate vulnerabilities in XML parsing.. SUSE pam-modules update, Linux security patch, SUSE vulnerability management. . LinuxSecurity.com Team
Security fix for CVE-2015-3245, CVE-2015-3246. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12301 2015-07-29 21:45:05 -------------------------------------------------------------------------------- Name : libuser Product : Fedora 22 Version : 0.62 Release : 1.fc22 URL : https://fedoraproject.org/wiki/Infrastructure/Fedorahosted-retirement Summary : A user and group account administration library Description : The libuser library implements a standardized interface for manipulating and administering user and group accounts. The library uses pluggable back-ends to interface to its data sources. Sample applications modeled after those included with the shadow password suite are included. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-3245, CVE-2015-3246 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Miloslav TrmaÄ - 0.62-1 - Update to libuser-0.62 Resolves: #1246225 (CVE-2015-3245, CVE-2015-3246) * Wed Jun 17 2015 Fedora Release Engineering - 0.61-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Wed Mar 25 2015 Miloslav TrmaÄ - 0.61-1 - Update to libuser-0.61, notably adding Python 3 bindings Resolves: #1014555 - Filter out libuser plugin and Python extension Provides: * Sat Feb 21 2015 Till Maas - 0.60-7 - Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code -------------------------------------------------------------------------------- References: [ 1 ] Bug #1233043 - CVE-2015-3245 libuser does not filter newline characters in the GECOS field https://bugzilla.redhat.com/show_bug.cgi?id=1233043 [ 2 ] Bug #1233052 - CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file https://bugzilla.redhat.com/show_bug.cgi?id=1233052 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libuser' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-278 2006-04-08 ---------------------------------------------------------------------Product : Fedora Core 5 Name : shadow-utils Version : 4.0.14 Release : 6.FC5 Summary : Utilities for managing accounts and shadow password files. Description : The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. The pwconv command converts passwords to the shadow password format. The pwunconv command unconverts shadow passwords and generates an npasswd file (a standard UNIX password file). The pwck command checks the integrity of password and shadow files. The lastlog command prints out the last login times for all users. The useradd, userdel, and usermod commands are used for managing user accounts. The groupadd, groupdel, and groupmod commands are used for managing group accounts. ---------------------------------------------------------------------* Tue Apr 4 2006 Peter Vrabec 2:4.0.14-6.FC5 - properly notify nscd to flush its cache(#186803) ---------------------------------------------------------------------This update can be downloaded from: e6c696a2bd1ff2ef16a17a2550477427638844f0 SRPMS/shadow-utils-4.0.14-6.FC5.src.rpm a5bb253779a07c172187e6ba5ef6170ef7a3a09e ppc/shadow-utils-4.0.14-6.FC5.ppc.rpm 0f4bfb7570784e2d1063df6243bba611efa24124 ppc/debug/shadow-utils-debuginfo-4.0.14-6.FC5.ppc.rpm 2c6bf0476706fbef4d1cbe000af24ec931afbe29 x86_64/shadow-utils-4.0.14-6.FC5.x86_64.rpm 4ad4180f55776678251d322cb78e22d4c5b349cd x86_64/debug/shadow-utils-debuginfo-4.0.14-6.FC5.x86_64.rpm eb1a1128e9b6a0f4eb7b31bd7513c031e2aa5e88 i386/shadow-utils-4.0.14-6.FC5.i386.rpm edd6449b35df46da50167d7ff34320bc42bda69d i386/debug/shadow-utils-debuginfo-4.0.14-6.FC5.i386.rpm This update canbe installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-201 2006-03-22 ---------------------------------------------------------------------Product : Fedora Core 5 Name : shadow-utils Version : 4.0.14 Release : 5.FC5 Summary : Utilities for managing accounts and shadow password files. Description : The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. The pwconv command converts passwords to the shadow password format. The pwunconv command unconverts shadow passwords and generates an npasswd file (a standard UNIX password file). The pwck command checks the integrity of password and shadow files. The lastlog command prints out the last login times for all users. The useradd, userdel, and usermod commands are used for managing user accounts. The groupadd, groupdel, and groupmod commands are used for managing group accounts. ---------------------------------------------------------------------* Wed Mar 22 2006 Peter Vrabec 2:4.0.14-5.FC5 * FC5 update * Fri Mar 10 2006 Peter Vrabec 2:4.0.14-4 - fix lrename() function to handle relative symlinks too * Tue Mar 7 2006 Peter Vrabec 2:4.0.14-3 - set default umask to 077 in login.defs * Mon Mar 6 2006 Peter Vrabec 2:4.0.14-2 - use lrename() function, which follow a destination symbolic link(#181977) ---------------------------------------------------------------------This update can be downloaded from: b2c9e91005f1a4198fd4286c792e2d833f543be1 SRPMS/shadow-utils-4.0.14-5.FC5.src.rpm e9817689bc543e7655c831b205e62f09a3679638 ppc/shadow-utils-4.0.14-5.FC5.ppc.rpm 12e0f7f9159b760b012a399de0e42642eede49a8 ppc/debug/shadow-utils-debuginfo-4.0.14-5.FC5.ppc.rpm 27a88bf5b29df69a69ebf1db3009105913ad4cf3 x86_64/shadow-utils-4.0.14-5.FC5.x86_64.rpm 92984c115dfa1b6289f2c00ae82c903f24e0dc8f x86_64/debug/shadow-utils-debuginfo-4.0.14-5.FC5.x86_64.rpm df13ffef232ee2638c773fc517d4da060e048844 i386/shadow-utils-4.0.14-5.FC5.i386.rpm f52936f4e7dffa3e33bee1fd1d184d1469ff9990 i386/debug/shadow-utils-debuginfo-4.0.14-5.FC5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-145 2006-03-13 ---------------------------------------------------------------------Product : Fedora Core 4 Name : shadow-utils Version : 4.0.12 Release : 8.FC4 Summary : Utilities for managing accounts and shadow password files. Description : The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. The pwconv command converts passwords to the shadow password format. The pwunconv command unconverts shadow passwords and generates an npasswd file (a standard UNIX password file). The pwck command checks the integrity of password and shadow files. The lastlog command prints out the last login times for all users. The useradd, userdel, and usermod commands are used for managing user accounts. The groupadd, groupdel, and groupmod commands are used for managing group accounts. ---------------------------------------------------------------------* Fri Mar 10 2006 Peter Vrabec 2:4.0.12-8.FC4 - fix lrename() function to handle relative symlinks too - set default umask to 077 in login.defs (#185290) ---------------------------------------------------------------------This update can be downloaded from: dac93c1d85262bd2c3a9f3d1e905e4ae997beb93 SRPMS/shadow-utils-4.0.12-8.FC4.src.rpm eb9ca53598a1df55acdb30f3c86dca1e6735c404 ppc/shadow-utils-4.0.12-8.FC4.ppc.rpm 318179228a392bdb09ddb313efd9496511f7b2e3 ppc/debug/shadow-utils-debuginfo-4.0.12-8.FC4.ppc.rpm cb02358b34875e1061a8b0b5d9440d7183b8e3b2 x86_64/shadow-utils-4.0.12-8.FC4.x86_64.rpm 600b561ecfc2f686ca859e019abd45794f925298 x86_64/debug/shadow-utils-debuginfo-4.0.12-8.FC4.x86_64.rpm d3e6bee134b4f1b01c9b44839e25291de745fc64 i386/shadow-utils-4.0.12-8.FC4.i386.rpm 73fd7084a289935803b9a41b245fdcc609eb007f i386/debug/shadow-utils-debuginfo-4.0.12-8.FC4.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-135 2006-03-06 ---------------------------------------------------------------------Product : Fedora Core 4 Name : shadow-utils Version : 4.0.12 Release : 7.FC4 Summary : Utilities for managing accounts and shadow password files. Description : The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. The pwconv command converts passwords to the shadow password format. The pwunconv command unconverts shadow passwords and generates an npasswd file (a standard UNIX password file). The pwck command checks the integrity of password and shadow files. The lastlog command prints out the last login times for all users. The useradd, userdel, and usermod commands are used for managing user accounts. The groupadd, groupdel, and groupmod commands are used for managing group accounts. ---------------------------------------------------------------------* Mon Mar 6 2006 Peter Vrabec 2:4.0.12-7.FC4 - use lrename() function, which follow a destination symbolic link(#181977) ---------------------------------------------------------------------This update can be downloaded from: ab91b42c5dccca4f676b8830653cd842c2191942 SRPMS/shadow-utils-4.0.12-7.FC4.src.rpm 3133ba6f68188628622a0f3617d90ece03fbfb4f ppc/shadow-utils-4.0.12-7.FC4.ppc.rpm 7c1806334ff3757e76f49a05b0545c83196b812e ppc/debug/shadow-utils-debuginfo-4.0.12-7.FC4.ppc.rpm 7c7348fd5dd28d246d6684f4d4011b0268139b6c x86_64/shadow-utils-4.0.12-7.FC4.x86_64.rpm 271f7129bfe11c361d805c0ae1b6e879dd991068 x86_64/debug/shadow-utils-debuginfo-4.0.12-7.FC4.x86_64.rpm 40a3b31407cd963c8479276f9a6755085148ebfb i386/shadow-utils-4.0.12-7.FC4.i386.rpm 4c7f6313001691bc5ecca8d40b47f40d9b19d5d9 i386/debug/shadow-utils-debuginfo-4.0.12-7.FC4.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-698 2005-08-17 ---------------------------------------------------------------------Product : Fedora Core 4 Name : shadow-utils Version : 4.0.7 Release : 10.FC4 Summary : Utilities for managing accounts and shadow password files. Description : The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. The pwconv command converts passwords to the shadow password format. The pwunconv command unconverts shadow passwords and generates an npasswd file (a standard UNIX password file). The pwck command checks the integrity of password and shadow files. The lastlog command prints out the last login times for all users. The useradd, userdel, and usermod commands are used for managing user accounts. The groupadd, groupdel, and groupmod commands are used for managing group accounts. ---------------------------------------------------------------------* Mon Aug 8 2005 Peter Vrabec 2:4.0.7-10.FC4 - do not copy files from skel directory if home directory already exist (#89591,#80242) ---------------------------------------------------------------------This update can be downloaded from: 8f218c610919e452813100c22ce6055b SRPMS/shadow-utils-4.0.7-10.FC4.src.rpm cac17aff8f428dd206eb4200ca772b14 ppc/shadow-utils-4.0.7-10.FC4.ppc.rpm a01e1caab022406796751f406f530efb ppc/debug/shadow-utils-debuginfo-4.0.7-10.FC4.ppc.rpm 28bc08671a649de5f6b99830290817e8 x86_64/shadow-utils-4.0.7-10.FC4.x86_64.rpm 4b743e3ae8e6572842c3ad0ed4012170 x86_64/debug/shadow-utils-debuginfo-4.0.7-10.FC4.x86_64.rpm 367a6b43f7278ef7e3dab7e7aedb34af i386/shadow-utils-4.0.7-10.FC4.i386.rpm 87f266afe71415ad1801b9a924263351 i386/debug/shadow-utils-debuginfo-4.0.7-10.FC4.i386.rpm This update can also beinstalled with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.