Description
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4130-1 | shadow security update |
EUVD |
EUVD-2023-54493 | A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory. |
Ubuntu USN |
USN-6640-1 | shadow vulnerability |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 17 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Redhat
Subscribe
Codeready Linux Builder
Subscribe
Codeready Linux Builder For Arm64
Subscribe
Codeready Linux Builder For Ibm Z Systems
Subscribe
Codeready Linux Builder For Power Little Endian
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux For Arm 64
Subscribe
Enterprise Linux For Ibm Z Systems
Subscribe
Enterprise Linux For Power Little Endian
Subscribe
Rhel Eus
Subscribe
Shadow-maint
Subscribe
Shadow-utils
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-03T19:28:32.370Z
Reserved: 2023-08-30T17:16:27.137Z
Link: CVE-2023-4641
Updated: 2025-11-03T19:28:32.370Z
Status : Modified
Published: 2023-12-27T16:15:13.363
Modified: 2025-11-03T20:16:05.017
Link: CVE-2023-4641
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN