Advisories ยป MGASA-2017-0024

Updated shadow-utils packages fix security vulnerabilities

Publication date: 27 Jan 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-6251 , CVE-2016-6252


It was found that shadow-utils-4.2.1 had a potentially unsafe use of
getlogin with the concern that the utmp entry might have a spoofed
username associated with a correct uid (CVE-2016-6251).

It was found that shadow-utils-4.2.1 had an incorrect integer handling
problem where it looks like the int wrap is exploitable as a LPE, as the
kernel is using 32bit uid's that are truncated from unsigned longs
(64bit on x64) as returned by simple_strtoul() [map_write()].