Opened 2 years ago

Closed 2 years ago

#4976 closed enhancement (fixed)

shadow-4.11.1

Reported by: Bruce Dubbs Owned by: lfs-book
Priority: high Milestone: 11.1
Component: Book Version: git
Severity: normal Keywords:
Cc:

Description

v4.11

Changelog:

  • Handle possible TOCTTOU issues in usermod/userdel
    • (CVE-2013-4235)
    • Use O_NOFOLLOW when copying file
    • Kill all user tasks in userdel
  • Fix useradd -D segfault
  • Clean up obsolete libc feature-check ifdefs
  • Fix -fno-common build breaks due to duplicate Prog declarations
  • Have single date_to_str definition
  • Fix libsubid SONAME version
  • Clarify licensing info, use SPDX.

v4.11.1

Changelog:

  • build: include lib/shadowlog_internal.h in dist tarballs

======

The recent patch to shadow is no longer needed.

Change History (4)

comment:1 by pierre, 2 years ago

Summary: shadow-4.11.1 (Wait for LFS)shadow-4.11.1

This is LFS :)

comment:2 by pierre, 2 years ago

Looks like the sed to libmisc/salt.c is unneeded now too.

comment:3 by Douglas R. Reno, 2 years ago

Priority: normalhigh

Marking as one priority up due to CVE-2013-4235.

comment:4 by Bruce Dubbs, 2 years ago

Resolution: fixed
Status: newclosed

Fixed at commit ade3efafc6caf69322c5fed47bc376c088f07a67

Package updates.
    Update to shadow-4.11.1.
    Update to readline-8.1.2.
    Update to meson-0.61.0.
    Update to libpipeline-1.5.5.
    Update to bash-5.1.16.
Note: See TracTickets for help on using tickets.