安全公告详情

NS-SA-2025-0198

2025-07-25 16:49:52

简介

low: shadow/util-linux security update

严重级别

low

主题

An update for shadow/util-linux is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of low. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

shadow:
util-linux:


Security Fix(es):
shadow: A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.(CVE-2023-4641)
shadow: bugfix
util-linux: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.(CVE-2024-28085)
util-linux: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • shadow
  • util-linux

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["shadow-core-4.14.3-2.zncgsl7.31.x86_64.rpm","shadow-4.14.3-2.zncgsl7.31.x86_64.rpm"],"source":"shadow-4.14.3-2.zncgsl7.31.src.rpm"},{"binary":["util-linux-core-2.39.1-2.zncgsl7.5.x86_64.rpm","util-linux-2.39.1-2.zncgsl7.5.x86_64.rpm","libuuid-devel-2.39.1-2.zncgsl7.5.x86_64.rpm","libuuid-2.39.1-2.zncgsl7.5.x86_64.rpm","libsmartcols-2.39.1-2.zncgsl7.5.x86_64.rpm","libmount-devel-2.39.1-2.zncgsl7.5.x86_64.rpm","libmount-2.39.1-2.zncgsl7.5.x86_64.rpm","libfdisk-2.39.1-2.zncgsl7.5.x86_64.rpm","libblkid-devel-2.39.1-2.zncgsl7.5.x86_64.rpm","libblkid-2.39.1-2.zncgsl7.5.x86_64.rpm"],"source":"util-linux-2.39.1-2.zncgsl7.5.src.rpm"}]}]}

CVE

参考