Description
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Published: 2023-12-27
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4130-1 shadow security update
EUVD EUVD EUVD-2023-54493 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Ubuntu USN Ubuntu USN USN-6640-1 shadow vulnerability
History

Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Thu, 17 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Redhat Codeready Linux Builder Codeready Linux Builder For Arm64 Codeready Linux Builder For Ibm Z Systems Codeready Linux Builder For Power Little Endian Enterprise Linux Enterprise Linux For Arm 64 Enterprise Linux For Ibm Z Systems Enterprise Linux For Power Little Endian Rhel Eus
Shadow-maint Shadow-utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-03T19:28:32.370Z

Reserved: 2023-08-30T17:16:27.137Z

Link: CVE-2023-4641

cve-icon Vulnrichment

Updated: 2025-11-03T19:28:32.370Z

cve-icon NVD

Status : Modified

Published: 2023-12-27T16:15:13.363

Modified: 2025-11-03T20:16:05.017

Link: CVE-2023-4641

cve-icon Redhat

Severity : Low

Publid Date: 2023-06-17T00:00:00Z

Links: CVE-2023-4641 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses