Home > Security > Advisories

Advisories

Mandriva Advisories

Package name shadow-utils
Date January 10th, 2001
Advisory ID MDKSA-2001:007
Affected versions 6.0, 6.1, 7.0, 7.1, 7.2
Synopsis Updated shadow-utils packages fix potential temp file race

Problem Description

WireX discovered a potential temporary file race condition in the
useradd program contained in the shadow-utils package. The useradd
program creates it's temporary files in the protected directory
/etc/default, but if this directory is changed to world writable, a
problem could occur. This update corrects the problem.

Updated Packages

Mandrakelinux 6.0

 c8eeb7167bcdeff6e204c46d3adabb43  6.0/RPMS/shadow-utils-980403-7.1mdk.i586.rpm
31bd9d8cb7358ab147df02f7fd49365a  6.0/SRPMS/shadow-utils-980403-7.1mdk.src.rpm

Mandrakelinux 6.1

 bcb7fda83dc076caa7bb4b89b3c87cc9  6.1/RPMS/shadow-utils-980403-7.1mdk.i586.rpm
31bd9d8cb7358ab147df02f7fd49365a  6.1/SRPMS/shadow-utils-980403-7.1mdk.src.rpm

Mandrakelinux 7.0

 1a5a4e7b7c1dffe8a3dbdee8a2302da8  7.0/RPMS/shadow-utils-19990827-4.1mdk.i586.rpm
aefcce82330b0add83a3583aa0943cb4  7.0/SRPMS/shadow-utils-19990827-4.1mdk.src.rpm

Mandrakelinux 7.1

 2b09ae303792a3806ccd0d5598319b3b  7.1/RPMS/shadow-utils-19990827-4.1mdk.i586.rpm
aefcce82330b0add83a3583aa0943cb4  7.1/SRPMS/shadow-utils-19990827-4.1mdk.src.rpm

Mandrakelinux 7.2

 416d563bbbbbb4d81b02efa79331aa3e  7.2/RPMS/shadow-utils-19990827-8.1mdk.i586.rpm
3c9f388210b48dfdeb4eb1ec3dba5146  7.2/SRPMS/shadow-utils-19990827-8.1mdk.src.rpm

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.