A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
The problem can be corrected by upgrading the affected package to
version 1:4.0.3-28.5ubuntu6.1. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Martin Schulze and Steve Grubb discovered a flaw in the authentication
input validation of the "chfn" and "chsh" programs. This allowed
logged in users with an expired password to change their real name and
their login shell without having to change their password.
This flaw cannot lead to privilege escalation and does not allow to
modify account properties of other users, so the impact is relatively