[ubuntu/precise-security] shadow 1:4.1.4.2+svn3283-3ubuntu5.2 (Accepted)

Steve Langasek steve.langasek at canonical.com
Mon May 3 13:09:19 UTC 2021


shadow (1:4.1.4.2+svn3283-3ubuntu5.2) precise-security; urgency=medium

  * SECURITY UPDATE: preventing tty hijacking.
    - debian/patches/0001-Do_not_foward_controlling_terminal.patch
      No CVE is currently assigned. Upstream patch.
  [ Seth Arnold ]
  * SECURITY UPDATE: su could be used to kill arbitrary process.
    - debian/patches/CVE-2017-2616.patch: Check process's exit status before
      sending signal. This patch is a combined patch with original and
      regression patch
    - CVE-2017-2616

Date: 2017-06-24 01:20:17.965204+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Steve Langasek <steve.langasek at canonical.com>
https://launchpad.net/ubuntu/+source/shadow/1:4.1.4.2+svn3283-3ubuntu5.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list