-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 07 Apr 2025 12:38:46 +0200 Source: shadow Binary: libsubid-dev libsubid4 libsubid4-dbgsym login login-dbgsym passwd passwd-dbgsym uidmap uidmap-dbgsym Architecture: i386 Version: 1:4.13+dfsg1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Chris Hofstaedtler Description: libsubid-dev - subordinate id handling library -- shared library libsubid4 - subordinate id handling library -- shared library login - system login tools passwd - change and administer password and group data uidmap - programs to help use subuids Closes: 1034482 1051062 Changes: shadow (1:4.13+dfsg1-1+deb12u1) bookworm; urgency=medium . [ Balint Reczey ] * Cherry-pick upstream patch to fix gpasswd passwd leak (Closes: #1051062) CVE-2023-4641 * Cherry-pick upstream patch to fix chfn vulnerability (Closes: #1034482) CVE-2023-29383 * Fix valid_field() that regressed in upstream's chfn fix . [ Chris Hofstaedtler ] * Update Uploaders: field from unstable Checksums-Sha1: 12e809198a174923ed3b0c8e69856e6182cc07ce 235584 libsubid-dev_4.13+dfsg1-1+deb12u1_i386.deb 75dfbbd3ec2e897d55279362db8eeba634838ab1 146624 libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb f456b8bb36e1e8e639fe7d035e87f51cf5407a4d 217216 libsubid4_4.13+dfsg1-1+deb12u1_i386.deb 72c39b677a98ead90eb960181bf1bdeb389e66ef 104556 login-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb f7fa8516052acc332d91e6a6f36818545557279e 616992 login_4.13+dfsg1-1+deb12u1_i386.deb 679860a7a44db1578ca487159b9a3a62735e33f7 1265796 passwd-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb c6acc25727c5b91369235a20f034f6810a16bdb6 975560 passwd_4.13+dfsg1-1+deb12u1_i386.deb bcf7e1ae1aabed9ce1c4964d5e9da41d90879d3d 9410 shadow_4.13+dfsg1-1+deb12u1_i386-buildd.buildinfo 1901fa74d0b7e8363bcc0f43ee027b70d7d16b0d 95384 uidmap-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb 477aac2b0b35f3e0d50fe8bd622d4c86baef015a 191168 uidmap_4.13+dfsg1-1+deb12u1_i386.deb Checksums-Sha256: 1112d2503aa6b93721cd70d5aa44cd08636aea8e0fb312acaf5d971a7305b2d5 235584 libsubid-dev_4.13+dfsg1-1+deb12u1_i386.deb 49bfd139d076b1812dc8ccecfe0c0d4952c58c0494606db9077fea6ec9d43488 146624 libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb 481197fdc020b4ff1789aaa530a175689ca85cda8bdaf6d6d024e4451a20736b 217216 libsubid4_4.13+dfsg1-1+deb12u1_i386.deb adf91baa3fe284ee8573ab855dede8170d44401f11f969a72abf8e65375b58e4 104556 login-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb ffd41f842c12e796baa6f9c098902680acd7c26c39d870b2ca54d478bc030574 616992 login_4.13+dfsg1-1+deb12u1_i386.deb 1a4396197b97e1475655554461856deac3b9e0255816386e081c7882d55e5d0c 1265796 passwd-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb 316091f2dcaf3103fa52b2db8af21db796fb078907fa9921582e7977959046ba 975560 passwd_4.13+dfsg1-1+deb12u1_i386.deb 56df5d730d96c42ae1ca9afd773af9725b51e51b558847d421e94e3738959e10 9410 shadow_4.13+dfsg1-1+deb12u1_i386-buildd.buildinfo 58443ad451ba42910efa36b342b28882476267251daa2be079192f5c06344752 95384 uidmap-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb cfeaf164ed270c1010331447f03e9ab0b8cda153368933f1e3c2d07d1249c179 191168 uidmap_4.13+dfsg1-1+deb12u1_i386.deb Files: aa3fc3c16c29f9a8c43cdf11f64c88a6 235584 libdevel optional libsubid-dev_4.13+dfsg1-1+deb12u1_i386.deb a1e51ac0f310c05bea3fd4883d342d02 146624 debug optional libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb c9c561c4f8f2e5103ceffc3b58cbb97b 217216 libs optional libsubid4_4.13+dfsg1-1+deb12u1_i386.deb 9fdb9eb3f293a9bb9de7a75fa577041b 104556 debug optional login-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb 580b6ca97aa3128e9884175a49340b3d 616992 admin required login_4.13+dfsg1-1+deb12u1_i386.deb 6c0fb4a5388632e5d5f9d4dd555d5223 1265796 debug optional passwd-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb 1db2bc6f333994e37db185ab7930cf61 975560 admin required passwd_4.13+dfsg1-1+deb12u1_i386.deb 80969e12076c9e0205d07c83fd37481f 9410 admin required shadow_4.13+dfsg1-1+deb12u1_i386-buildd.buildinfo 8695a554fb2536280695e146710e79a2 95384 debug optional uidmap-dbgsym_4.13+dfsg1-1+deb12u1_i386.deb 9dac19745b10e0907293c45d1c9dd248 191168 admin optional uidmap_4.13+dfsg1-1+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXNeYFUF3FbHcrtSeIy3Pg040HrAFAmgfjZgACgkQIy3Pg040 HrC9VA//WCvJvnPHE0AMZkAHzRu3vKurE/8OoWrX4Jv8cPEMs3iNCfsxOHeXhBu9 4lz8jDxwcYAmYK0kNFdSamj9pulb8hKBqWYpzwyRekCo7+8uj+zZtl6X0qU2oWJW N74IOs79wEmRHifEd9zF6XCNos8+IFlZNt3sW/pSCOW1HHnRlGMYzGp0Qzr9Z9MU U9sDZyKBC+uIfYW3ycEJ7RPV1tdNjMgTbwjyng5BEVanzod0nsRbyEva82XQKT7f DQO97crG60VsiB8bqQ1gpimH51KvtCbmge6zdTVWSFBo05xJsJXCE5bk6fU4vrJ+ f/mOYm6aC+7cLvUdcTcZ4JfZxQfMjebanRHWiOj1sxud82LBePBSV+A9lXmSz0vx GLDIDpbDXJ6QTDsw1RlVtogXsJXaXtKT8+M5c+ySPfQZppc20onUlSADa5+hXhxo 4XzDBvjz3ylbSF6wfq8lvKHWmwWNUKZuJzCBwk5MzqB5ZK1AmS9hFyrSVYxWWkWj 3DURzXX7im5sAYagSXut/28LCCAtzwpULJLihdlDlbNaA/RM7XSsS3SxWa2GfwEu khN11tEXqIvUh/rQsoxCJsqbDHG74iTyv6yPM/vwU3jp7ZhcbC1RUzzNFPQwtxcb a0YKskbuv+zUeN9oyN4xkHzp3tBa6DhQfkLMfyy8bYwLOIFSOqw= =5He7 -----END PGP SIGNATURE-----