-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 07 Apr 2025 12:38:46 +0200 Source: shadow Binary: libsubid-dev libsubid4 libsubid4-dbgsym login login-dbgsym passwd passwd-dbgsym uidmap uidmap-dbgsym Architecture: amd64 Version: 1:4.13+dfsg1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Chris Hofstaedtler Description: libsubid-dev - subordinate id handling library -- shared library libsubid4 - subordinate id handling library -- shared library login - system login tools passwd - change and administer password and group data uidmap - programs to help use subuids Closes: 1034482 1051062 Changes: shadow (1:4.13+dfsg1-1+deb12u1) bookworm; urgency=medium . [ Balint Reczey ] * Cherry-pick upstream patch to fix gpasswd passwd leak (Closes: #1051062) CVE-2023-4641 * Cherry-pick upstream patch to fix chfn vulnerability (Closes: #1034482) CVE-2023-29383 * Fix valid_field() that regressed in upstream's chfn fix . [ Chris Hofstaedtler ] * Update Uploaders: field from unstable Checksums-Sha1: 5426cebd125cae6612f73dc11e1724766b07e52b 227200 libsubid-dev_4.13+dfsg1-1+deb12u1_amd64.deb 0d4143144074e50af07ece0a7b997443c7d426e8 171096 libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb e64990e70e39b3fe144e52fdb989482adcd69e0d 211184 libsubid4_4.13+dfsg1-1+deb12u1_amd64.deb 9a2af2b1f714dc828c188c6b485dab49e439fa2c 120636 login-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 29493a4c15534eabf3e1bc670863d5e4a3ad8250 615896 login_4.13+dfsg1-1+deb12u1_amd64.deb 50572a2023d6135cd23b956ad41f86342952bb07 1489252 passwd-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 862c9a868bbc71a729ab8d89afbab43ba18e2080 972056 passwd_4.13+dfsg1-1+deb12u1_amd64.deb bda5158b46e04cc361e5fa146aa975ece9e0db24 9494 shadow_4.13+dfsg1-1+deb12u1_amd64-buildd.buildinfo 0c8a717e427007d6ead91303a3ed4969236b8772 109516 uidmap-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 7ff36ac0521f18f294ea9e75b55209becd47d57b 188664 uidmap_4.13+dfsg1-1+deb12u1_amd64.deb Checksums-Sha256: bf8251c36a5eecd8531ffc3a63cf753a4f4e87e50ac41d8c20500ffc6c5070ee 227200 libsubid-dev_4.13+dfsg1-1+deb12u1_amd64.deb 9745642a1d950b6ef8ec7899cbe2529e2ffd2e9f33c15d9bbe6cb7f81fd2bd2c 171096 libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb d56e00c4991b9f20d8af36d0422302647faa8c63eb3eea3d2633312538950693 211184 libsubid4_4.13+dfsg1-1+deb12u1_amd64.deb 71c52def08dac96df9c6b9a569aee36f87dfb0f56704e66759a9f917ea267aa9 120636 login-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 411ce6de8a354ad35f9f57ba73c56dbdb70e6a821f7f2d10296b262a6ec5be7d 615896 login_4.13+dfsg1-1+deb12u1_amd64.deb a9f5ee815e8c42f939ac90552d3eb5ef8ea7bc39e5d25f756a66302e4314d429 1489252 passwd-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb bf6fc6e59a5452113d9d582d100d289654914d2b4bd8f2c177f8ef814a3947ed 972056 passwd_4.13+dfsg1-1+deb12u1_amd64.deb 227bf1a4bcb5d20838aba9489bd9fcb6614cefc7580e97dc8f06145127b95bdf 9494 shadow_4.13+dfsg1-1+deb12u1_amd64-buildd.buildinfo 2e0d53d0f833d53c50b672e5e7d2f8e7e8f570b0db972f38a97e1c38f634b7d4 109516 uidmap-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 14ed5f08bf3c2cd4a61043b056f39fdc637656ae60f5c0e498235a5bbfa41047 188664 uidmap_4.13+dfsg1-1+deb12u1_amd64.deb Files: 351e97283dd46e97df67fee63d5e5c05 227200 libdevel optional libsubid-dev_4.13+dfsg1-1+deb12u1_amd64.deb 8f4c27992084c7e7c37d90c6ec5f4430 171096 debug optional libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb de5779ad57fb9268f8e885eb9d48af77 211184 libs optional libsubid4_4.13+dfsg1-1+deb12u1_amd64.deb 7b0e3758023bef4d236b9cd22735ed48 120636 debug optional login-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 1e64d78ba41a1cd8802c02a3a164138a 615896 admin required login_4.13+dfsg1-1+deb12u1_amd64.deb 0347b007529a30457aa1bb0de229f2bd 1489252 debug optional passwd-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb f24397a5bc85f845e1b797ffabe92c3c 972056 admin required passwd_4.13+dfsg1-1+deb12u1_amd64.deb fed115a7794cde9b47b7efa855be8779 9494 admin required shadow_4.13+dfsg1-1+deb12u1_amd64-buildd.buildinfo 0ce11ce71aa68521e9fa3d0c6d5f9f5d 109516 debug optional uidmap-dbgsym_4.13+dfsg1-1+deb12u1_amd64.deb 9388f540afa565e993e148659d78cc11 188664 admin optional uidmap_4.13+dfsg1-1+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmgfjQIACgkQEbCLukZn 24pdUhAAiWK2xoV/1KQYGEnGMxolD7aOUc0fi6ZdxznQjRwS7KnCz8kH1DiKYsfa zXUX/E66TX/zCokjzTeGhRrMecpzaFz/aafAMGKwtACB9cmMxOXGIkEpJy9Ip7YJ jCkTnTSouDcTdY+C6LXdCnk6dENk22fGsBs2IJDyGZDAKeUWDGZuWTHbS7FBceO+ K7YlTeWWpTfTq2xcPJGgYMRU5XUO3ppTTpQfdRb6YcMp2prCYda4EG0YWs/fAP2g F6Dmyv6InG4HmidivaviinHrXma7ezDeq62qfwngL0WLDdjzHbh1fwDvMMSJce5M ixMQQtTXp3WtXFQqnAGCTOfV5pmGq4lOBysE7/9ddo/NMNCrjlf9duZQmrOvjB0O BocN37vT2ZRm4YymcfqHF2oFhU4Kzq9Zii+tu3dt2gI5QVu64Kbj2c1WaKOJoUrC EVnhdR1bpSgACCg7sZfRk3euV9tqSJFAJiOTeKJMlAojWXpAl+wC2eH17Gb/UqV8 1lzVLrDPT8kjklOspCoQ8vGNgDnbyyBjqWksIVjDk7CT9nRFgDmToDkXO1f5stuM fiu+MWZnvNQHnL5fbFHt681rkzx/iJCXH4U7oMieOmfYNz8xxK64RTr7zXcZXBmv 1vDoeDRJ/8viV5CJse2OKfXwzs/LedXbpMA20QG2hbbA4J+6Wyc= =Z/11 -----END PGP SIGNATURE-----