[ubuntu/natty] shadow 1:4.1.4.2+svn3283-2ubuntu3 (Accepted)

Kees Cook kees at ubuntu.com
Tue Feb 15 22:25:28 UTC 2011


shadow (1:4.1.4.2+svn3283-2ubuntu3) natty; urgency=low

  * SECURITY UPDATE: could inject NIS groups memberships into /etc/passwd.
    - debian/patches/300_CVE-2011-0721: reject newlines in GECOS updates.
    - CVE-2011-0721

Date: Tue, 15 Feb 2011 13:57:01 -0800
Changed-By: Kees Cook <kees at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/shadow/1:4.1.4.2+svn3283-2ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Feb 2011 13:57:01 -0800
Source: shadow
Binary: passwd login
Architecture: source
Version: 1:4.1.4.2+svn3283-2ubuntu3
Distribution: natty
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Kees Cook <kees at ubuntu.com>
Description: 
 login      - system login tools
 passwd     - change and administer password and group data
Changes: 
 shadow (1:4.1.4.2+svn3283-2ubuntu3) natty; urgency=low
 .
   * SECURITY UPDATE: could inject NIS groups memberships into /etc/passwd.
     - debian/patches/300_CVE-2011-0721: reject newlines in GECOS updates.
     - CVE-2011-0721
Checksums-Sha1: 
 ab4258d1c4243f087f24ac0aba5534e39648ce2c 2362 shadow_4.1.4.2+svn3283-2ubuntu3.dsc
 08344ee80af3611170349133c11ac494bc4d9f36 336868 shadow_4.1.4.2+svn3283-2ubuntu3.diff.gz
Checksums-Sha256: 
 0b791d88e76fa031bd07affdf9e8c75cdf48801605f03dae6c3eb078720d25a9 2362 shadow_4.1.4.2+svn3283-2ubuntu3.dsc
 e10420c57b01869bbffbb6287390d6d3ed121aa9585f6d4ce5361ec47c5d2f65 336868 shadow_4.1.4.2+svn3283-2ubuntu3.diff.gz
Files: 
 fd13ce2ee6016cd992511a2d0be8b89b 2362 admin required shadow_4.1.4.2+svn3283-2ubuntu3.dsc
 832759129b48b65d630e8c753654a7d5 336868 admin required shadow_4.1.4.2+svn3283-2ubuntu3.diff.gz
Original-Maintainer: Shadow package maintainers <pkg-shadow-devel at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Kees Cook <kees at outflux.net>

iQIcBAEBCgAGBQJNWvmiAAoJEIly9N/cbcAmv/oP+wXqdb54Uu0K/YNhQCS6paNh
xy19SiVAXC/+rw9+PcU7seNZuhyjSu6o8XWv5docrSX6WauYstHca9Txas2+DEq5
1FpD6LYYyUbQuWRk3/SigC3w5hh8dvXXsJBUniI87xXErofMfsD5APIwoZorf7Qs
fH+oCaPOi783XO8XBgt62TGfocj8t6Fswj0LZStWpfd2eZalNE6bCKOR6DEYjQsU
2RZ4lRsTy+AT6RXhar0mI7+lgk93t+sNJAyUYh1RxvtaudIT3DKUCZIkUh6rIxUy
GxHTEo2GjQvLq+391tOTP+8uCFF45qVb0AMMTteBoJC67BaGwUyePrFuNB6TNhnL
ZahpNMmBvytReNfVv0chI07Hcuq1gYzuqEFJCqbA8eRK3Rtn4w2mN4XEXUXLdJwC
aARBDN8FxJv7JtkCsykELvKdb8BRPtlBFbh6fyepJaWjPcCzNm+iASugpUaold+l
nCSBFiCR+poTWHUVgiNUWNFRzGTNcquoUA20NvkAla4UgnM56HFemwFVbL+nERRP
3XmLy3ZGEQdw01txqFmUiOkPMFgCcyxg8l1pyj+2B6E9WHqj7ul606Z21BQ5CWkC
lmeAaCHC89wAIeVr1tc4u/u9Ug5d2oiElMUtkiaoUVftWmycF3KSAb/sqKCR+8/9
izdtbKqjyqwxv/XDyB4G
=JSws
-----END PGP SIGNATURE-----


More information about the Natty-changes mailing list