Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.703793
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-3793-1)
Summary:The remote host is missing an update for the Debian 'shadow' package(s) announced via the DSA-3793-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'shadow' package(s) announced via the DSA-3793-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in the shadow suite. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2016-6252

An integer overflow vulnerability was discovered, potentially allowing a local user to escalate privileges via crafted input to the newuidmap utility.

CVE-2017-2616

Tobias Stoeckmann discovered that su does not properly handle clearing a child PID. A local attacker can take advantage of this flaw to send SIGKILL to other processes with root privileges, resulting in denial of service.

For the stable distribution (jessie), these problems have been fixed in version 1:4.2-3+deb8u3.

We recommend that you upgrade your shadow packages.

Affected Software/OS:
'shadow' package(s) on Debian 8.

Solution:
Please install the updated package(s).

CVSS Score:
4.7

CVSS Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6252
BugTraq ID: 92055
http://www.securityfocus.com/bid/92055
Debian Security Information: DSA-3793 (Google Search)
http://www.debian.org/security/2017/dsa-3793
https://security.gentoo.org/glsa/201706-02
http://www.openwall.com/lists/oss-security/2016/07/19/7
http://www.openwall.com/lists/oss-security/2016/07/19/6
http://www.openwall.com/lists/oss-security/2016/07/20/2
http://www.openwall.com/lists/oss-security/2016/07/25/7
Common Vulnerability Exposure (CVE) ID: CVE-2017-2616
BugTraq ID: 96404
http://www.securityfocus.com/bid/96404
https://www.debian.org/security/2017/dsa-3793
RedHat Security Advisories: RHSA-2017:0654
http://rhn.redhat.com/errata/RHSA-2017-0654.html
RedHat Security Advisories: RHSA-2017:0907
https://access.redhat.com/errata/RHSA-2017:0907
http://www.securitytracker.com/id/1038271
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.