Bug 147570 - Unauthorized account properties modification (chfn and chsh)
Unauthorized account properties modification (chfn and chsh)
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: shadow-utils (Show other bugs)
rawhide
All Linux
medium Severity medium
: ---
: ---
Assigned To: Peter Vrabec
David Lawrence
http://cvs.pld.org.pl/shadow/NEWS?rev...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-02-09 08:43 EST by Marcin Garski
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-03-04 05:02:33 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Marcin Garski 2005-02-09 08:43:07 EST
shadow-4.0.5 has fixed securirty bug in libmisc/pwdcheck.c which allow
unauthorized account properties modification. Affected tools: chfn and
chsh. See URL for changelog.

Please consider updating shadow-utils to 4.0.7 version (as I know this
is how bugs are fixed in FC, package is updated to newer version
instead of backporting patch to old version), the newer version can
and probably will fix some open bugs on bugzilla.

Note You need to log in before you can comment on or make changes to this bug.