Explore top 10 tips to secure your open-source projects now. Read More
×
Several vulnerabilities were discovered in the shadow suite of login tools. An attacker may extract a password from memory in limited situations, and confuse an administrator inspecting /etc/passwd from within a terminal. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4130-1
* bsc#1228770 Cross-References: * CVE-2013-4235 . # Security update for shadow Announcement ID: SUSE-SU-2025:0292-1 Release Date: 2025-01-29T22:41:58Z Rating: moderate References: * bsc#1228770 Cross-References: * CVE-2013-4235 CVSS scores: * CVE-2013-4235 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2013-4235 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for shadow fixes the following issues: * Fixed not copying of skel files (bsc#1228770) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-292=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-292=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-292=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-292=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 * SUSE Enterprise Storage 7.1 (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Enterprise Storage 7.1(aarch64 x86_64) * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 ## References: * https://www.suse.com/security/cve/CVE-2013-4235.html * https://bugzilla.suse.com/show_bug.cgi?id=1228770 . Security revision for shadow; resolves a medium concern regarding update procedures for SUSE offerings. Refer to the information for specifics.. SUSE Security Update, Shadow Patch, SUSE Linux Enterprise, Security Advisory, Shadow Vulnerability Fix. . LinuxSecurity.com Team
* bsc#1144060 * bsc#1176006 * bsc#1188307 * bsc#1203823 * bsc#1205502 . # Security update for shadow Announcement ID: SUSE-SU-2024:1007-2 Rating: moderate References: * bsc#1144060 * bsc#1176006 * bsc#1188307 * bsc#1203823 * bsc#1205502 * bsc#1206627 * bsc#1210507 * bsc#1213189 * bsc#1214806 Cross-References: * CVE-2023-29383 * CVE-2023-4641 CVSS scores: * CVE-2023-29383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-29383 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2023-4641 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2023-4641 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves two vulnerabilities and has seven security fixes can now be installed. ## Description: This update for shadow fixes the following issues: * CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507). * CVE-2023-4641: Fixed possible password leak during passwd(1) change (bsc#1214806). The following non-security bugs were fixed: * bsc#1176006: Fix chage date miscalculation * bsc#1188307: Fix passwd segfault * bsc#1203823: Remove pam_keyinit from PAM config files * bsc#1213189: Change lock mechanism to file locking to prevent lock files after power interruptions * bsc#1206627: Add --prefix support to passwd, chpasswd and chage * bsc#1205502: useradd audit event user id field cannot be interpretedd ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1007=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (noarch) * login_defs-4.8.1-150500.3.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) *shadow-4.8.1-150500.3.3.1 * shadow-debugsource-4.8.1-150500.3.3.1 * shadow-debuginfo-4.8.1-150500.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-29383.html * https://www.suse.com/security/cve/CVE-2023-4641.html * https://bugzilla.suse.com/show_bug.cgi?id=1144060 * https://bugzilla.suse.com/show_bug.cgi?id=1176006 * https://bugzilla.suse.com/show_bug.cgi?id=1188307 * https://bugzilla.suse.com/show_bug.cgi?id=1203823 * https://bugzilla.suse.com/show_bug.cgi?id=1205502 * https://bugzilla.suse.com/show_bug.cgi?id=1206627 * https://bugzilla.suse.com/show_bug.cgi?id=1210507 * https://bugzilla.suse.com/show_bug.cgi?id=1213189 * https://bugzilla.suse.com/show_bug.cgi?id=1214806 . Apply the most recent SUSE security patch for shadow that addresses two critical vulnerabilities and incorporates necessary corrections.. SUSE Linux Enterprise Micro, Shadow Security Fix, Security Advisory. . LinuxSecurity.com Team
* bsc#1228770 Cross-References: * CVE-2013-4235 . # Security update for shadow Announcement ID: SUSE-SU-2024:2804-1 Rating: moderate References: * bsc#1228770 Cross-References: * CVE-2013-4235 CVSS scores: * CVE-2013-4235 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2013-4235 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for shadow fixes the following issues: * Fixed not copying of skel files (bsc#1228770) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-2804=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2804=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-2804=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-2804=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-2804=1 ## Package List: * openSUSE Leap 15.4 (noarch) * login_defs-4.8.1-150400.10.21.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * shadow-debuginfo-4.8.1-150400.10.21.1 * shadow-4.8.1-150400.10.21.1 * shadow-debugsource-4.8.1-150400.10.21.1 * openSUSE Leap 15.5 (noarch) * login_defs-4.8.1-150400.10.21.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390xx86_64) * shadow-debuginfo-4.8.1-150400.10.21.1 * shadow-4.8.1-150400.10.21.1 * shadow-debugsource-4.8.1-150400.10.21.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * login_defs-4.8.1-150400.10.21.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * shadow-debuginfo-4.8.1-150400.10.21.1 * shadow-4.8.1-150400.10.21.1 * shadow-debugsource-4.8.1-150400.10.21.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * login_defs-4.8.1-150400.10.21.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * shadow-debuginfo-4.8.1-150400.10.21.1 * shadow-4.8.1-150400.10.21.1 * shadow-debugsource-4.8.1-150400.10.21.1 * Basesystem Module 15-SP5 (noarch) * login_defs-4.8.1-150400.10.21.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * shadow-debuginfo-4.8.1-150400.10.21.1 * shadow-4.8.1-150400.10.21.1 * shadow-debugsource-4.8.1-150400.10.21.1 ## References: * https://www.suse.com/security/cve/CVE-2013-4235.html * https://bugzilla.suse.com/show_bug.cgi?id=1228770 . Stay secure by addressing the CVE-2013-4235 shadow vulnerability. Follow the provided steps to update your SUSE system and maintain protection. SUSE Security Update, Shadow Security Advisory, Linux Security Patch. . LinuxSecurity.com Team
* bsc#916845 Cross-References: * CVE-2013-4235 . # Security update for shadow Announcement ID: SUSE-SU-2024:2805-1 Rating: moderate References: * bsc#916845 Cross-References: * CVE-2013-4235 CVSS scores: * CVE-2013-4235 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2013-4235 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for shadow fixes the following issues: * CVE-2013-4235: Fixed TOCTOU race condition (bsc#916845) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2805=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2805=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2805=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * shadow-debugsource-4.2.1-36.15.1 * shadow-debuginfo-4.2.1-36.15.1 * shadow-4.2.1-36.15.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * shadow-debugsource-4.2.1-36.15.1 * shadow-debuginfo-4.2.1-36.15.1 * shadow-4.2.1-36.15.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * shadow-debugsource-4.2.1-36.15.1 * shadow-debuginfo-4.2.1-36.15.1 * shadow-4.2.1-36.15.1 ## References: * https://www.suse.com/security/cve/CVE-2013-4235.html * https://bugzilla.suse.com/show_bug.cgi?id=916845 . Canonical has released a security patch forthe Linux kernel addressing CVE-2023-4567, classified as important, along with detailed installation instructions.. SUSE Linux, Shadow Update, Security Patch, Linux Advisory. . LinuxSecurity.com Team
* bsc#1228770 Cross-References: * CVE-2013-4235 . # Security update for shadow Announcement ID: SUSE-SU-2024:2806-1 Rating: moderate References: * bsc#1228770 Cross-References: * CVE-2013-4235 CVSS scores: * CVE-2013-4235 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2013-4235 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for shadow fixes the following issues: * Fixed not copying of skel files (bsc#1228770) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-2806=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-2806=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-2806=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-2806=1 ## Package List: * openSUSE Leap 15.3 (noarch) * login_defs-4.8.1-150300.4.18.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * shadow-4.8.1-150300.4.18.1 * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Micro 5.1 (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * shadow-4.8.1-150300.4.18.1 * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Micro 5.2 (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * shadow-4.8.1-150300.4.18.1 *shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * login_defs-4.8.1-150300.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * shadow-4.8.1-150300.4.18.1 * shadow-debuginfo-4.8.1-150300.4.18.1 * shadow-debugsource-4.8.1-150300.4.18.1 ## References: * https://www.suse.com/security/cve/CVE-2013-4235.html * https://bugzilla.suse.com/show_bug.cgi?id=1228770 . Significant enhancement for shadow addresses crucially rectifies issues affecting SUSE Linux Enterprise and openSUSE Leap versions.. SUSE Linux Enterprise, openSUSE, shadow update, moderate fixes, SUSE advisory. . LinuxSecurity.com Team
* bsc#1228770 Cross-References: * CVE-2013-4235 . # Security update for shadow Announcement ID: SUSE-SU-2024:2808-1 Rating: moderate References: * bsc#1228770 Cross-References: * CVE-2013-4235 CVSS scores: * CVE-2013-4235 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2013-4235 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for shadow fixes the following issues: * Fixed not copying of skel files (bsc#1228770) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-2808=1 openSUSE-SLE-15.6-2024-2808=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-2808=1 ## Package List: * openSUSE Leap 15.6 (noarch) * login_defs-4.8.1-150600.17.6.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * shadow-4.8.1-150600.17.6.1 * shadow-debugsource-4.8.1-150600.17.6.1 * shadow-debuginfo-4.8.1-150600.17.6.1 * Basesystem Module 15-SP6 (noarch) * login_defs-4.8.1-150600.17.6.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * shadow-4.8.1-150600.17.6.1 * shadow-debugsource-4.8.1-150600.17.6.1 * shadow-debuginfo-4.8.1-150600.17.6.1 ## References: * https://www.suse.com/security/cve/CVE-2013-4235.html * https://bugzilla.suse.com/show_bug.cgi?id=1228770 . A significant vulnerability fix for shadow in SUSE offerings resolving CVE-2013-4235 with detailed patch application guidelines.. SUSE PatchInstructions, Shadow Security Update, CVE-2013-4235 Fix. . LinuxSecurity.com Team
* bsc#1228770 Cross-References: * CVE-2013-4235 . # Security update for shadow Announcement ID: SUSE-SU-2024:2809-1 Rating: moderate References: * bsc#1228770 Cross-References: * CVE-2013-4235 CVSS scores: * CVE-2013-4235 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2013-4235 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap Micro 5.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for shadow fixes the following issues: * Fixed not copying of skel files (bsc#1228770) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-2809=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-2809=1 ## Package List: * openSUSE Leap Micro 5.5 (noarch) * login_defs-4.8.1-150500.3.9.1 * openSUSE Leap Micro 5.5 (aarch64 s390x x86_64) * shadow-4.8.1-150500.3.9.1 * shadow-debugsource-4.8.1-150500.3.9.1 * shadow-debuginfo-4.8.1-150500.3.9.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * login_defs-4.8.1-150500.3.9.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * shadow-4.8.1-150500.3.9.1 * shadow-debugsource-4.8.1-150500.3.9.1 * shadow-debuginfo-4.8.1-150500.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2013-4235.html * https://bugzilla.suse.com/show_bug.cgi?id=1228770 . Critical security enhancement for memory handling CVE-2020-12345 on Fedora platforms. Safeguard your environment with the newest update.. SUSE Shadow Update, System Security, Linux Patch Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.