Debian: New shadow packages fix privilege escalation
Posted by Benjamin D. Thomas   
Debian Updated package.
- --------------------------------------------------------------------------
Debian Security Advisory DSA 1150-1                                       Martin Schulze
August 12th, 2006             
- --------------------------------------------------------------------------

Package        : shadow
Vulnerability  : programming error
Problem type   : local
Debian-specific: no
CVE ID         : CVE-2006-2194
BugTraq ID     : 18849

A bug has been discovered in several packages that execute teh
setuid() system call without checking for sucess when trying to drop
privileges, which may fail with some PAM configurations.

For the stable distribution (sarge) this problem has been fixed in
version 4.0.3-31sarge8.

For the unstable distribution (sid) this problem has been fixed in
version 4.0.17-2.

We recommend that you upgrade your passwd package.

Debian GNU/Linux 3.1 alias sarge
- --------------------------------

  These files will probably be moved into the stable distribution on
  its next update.

