Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Ubuntu update for shadow Advisory Available in Danish 

Secunia Advisory: SA20966  
Release Date: 2006-07-06
Last Update: 2006-07-12

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:Ubuntu Linux 5.04
Ubuntu Linux 5.10
Ubuntu Linux 6.06


CVE reference:CVE-2006-3378 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
Ubuntu has issued an update for shadow. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions with escalated privileges.

For more information:
SA20950

Solution:
Apply updated packages.

Updated packages for Ubuntu 5.04:

Source archives:

http://security.ubuntu.com/ubuntu/poo...w/shadow_4.0.3-30.7ubuntu16.1.diff.gz
Size/MD5: 1161448 adba4705f1491691a39f471ffc92c09b
http://security.ubuntu.com/ubuntu/poo...hadow/shadow_4.0.3-30.7ubuntu16.1.dsc
Size/MD5: 786 f3f8c3843a16523e8b09bc73c664646e
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.3.orig.tar.gz
Size/MD5: 1045704 b52dfb2e5e8d9a4a2aae0ca1b266c513

Architecture independent packages:

http://security.ubuntu.com/ubuntu/poo...wd-udeb_4.0.3-30.7ubuntu16.1_all.udeb
Size/MD5: 67204 433e3ad008f269d3879b4b36e863b6b0

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo.../login_4.0.3-30.7ubuntu16.1_amd64.deb
Size/MD5: 172388 1ae1307fe20ec93ee5cda9674bff7d31
http://security.ubuntu.com/ubuntu/poo...passwd_4.0.3-30.7ubuntu16.1_amd64.deb
Size/MD5: 591158 07c3c7e5326d116619376f750191881c

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...w/login_4.0.3-30.7ubuntu16.1_i386.deb
Size/MD5: 162780 d65e55fb3fd9a6d8c58a8f0117a0b63d
http://security.ubuntu.com/ubuntu/poo.../passwd_4.0.3-30.7ubuntu16.1_i386.deb
Size/MD5: 513386 93d96b05b65825f12aa0c43c9a4c07ee

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...ogin_4.0.3-30.7ubuntu16.1_powerpc.deb
Size/MD5: 171348 0f3c8f157ac3b1717334521587cede0d
http://security.ubuntu.com/ubuntu/poo...sswd_4.0.3-30.7ubuntu16.1_powerpc.deb
Size/MD5: 558434 91148b7d12fc0a405ecc6009fddb8915

Updated packages for Ubuntu 5.10:

Source archives:

http://security.ubuntu.com/ubuntu/poo...hadow/shadow_4.0.3-37ubuntu10.diff.gz
Size/MD5: 1070307 8b2fb08f4314b8a5d7d0228e516d254e
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.3-37ubuntu10.dsc
Size/MD5: 877 dcd588a15b6a706215191df0b1aa91d7
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.3.orig.tar.gz
Size/MD5: 1045704 b52dfb2e5e8d9a4a2aae0ca1b266c513

Architecture independent packages:

http://security.ubuntu.com/ubuntu/poo...passwd-udeb_4.0.3-37ubuntu10_all.udeb
Size/MD5: 1828 82abf8eb28a61b8fbe00c0c85b85099a

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...adow/login_4.0.3-37ubuntu10_amd64.deb
Size/MD5: 180932 2cdc5bc553c305ad71601eab30d91ecc
http://security.ubuntu.com/ubuntu/poo...dow/passwd_4.0.3-37ubuntu10_amd64.deb
Size/MD5: 590358 afa8b5c3552db22b12ce6ed3ac16dc7e

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...hadow/login_4.0.3-37ubuntu10_i386.deb
Size/MD5: 172160 573cb37f61f18087fc2e42ee1e0a8c3a
http://security.ubuntu.com/ubuntu/poo...adow/passwd_4.0.3-37ubuntu10_i386.deb
Size/MD5: 515976 0fb3906bfd5a1c9992a34119460161d6

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...ow/login_4.0.3-37ubuntu10_powerpc.deb
Size/MD5: 180218 d71a7d3615c0433e9c9c360316d45619
http://security.ubuntu.com/ubuntu/poo...w/passwd_4.0.3-37ubuntu10_powerpc.deb
Size/MD5: 568772 e3599c6460d3fa76c141948e0dd0647f

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/poo...adow/login_4.0.3-37ubuntu10_sparc.deb
Size/MD5: 173624 ed7f31e26778d7b90825a8047dd132e9
http://security.ubuntu.com/ubuntu/poo...dow/passwd_4.0.3-37ubuntu10_sparc.deb
Size/MD5: 525696 1184279ca53d144f86b89d5c4a236492

Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/poo...adow/shadow_4.0.13-7ubuntu3.1.diff.gz
Size/MD5: 201154 5439f48ff6e7a91d78da688d9eaec0e9
http://security.ubuntu.com/ubuntu/poo...s/shadow/shadow_4.0.13-7ubuntu3.1.dsc
Size/MD5: 887 210a8df854ade3afc11536ed918e9030
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.13.orig.tar.gz
Size/MD5: 1622557 034fab52e187e63cb52f153bb7f304c8

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/poo...dow/login_4.0.13-7ubuntu3.1_amd64.deb
Size/MD5: 249324 3041a38bb86df7ffb40b73952e498684
http://security.ubuntu.com/ubuntu/poo...ow/passwd_4.0.13-7ubuntu3.1_amd64.deb
Size/MD5: 683116 41b202a0066df6fe7b0e76e0ae660a5c

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/poo...adow/login_4.0.13-7ubuntu3.1_i386.deb
Size/MD5: 240808 fc035322e94f8f1a6ffef669b4358ec7
http://security.ubuntu.com/ubuntu/poo...dow/passwd_4.0.13-7ubuntu3.1_i386.deb
Size/MD5: 615996 b36322bc8a65657af67057b5bb86cb0d

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/poo...w/login_4.0.13-7ubuntu3.1_powerpc.deb
Size/MD5: 251236 29d6b23dffd5b4431aac241012dd6158
http://security.ubuntu.com/ubuntu/poo.../passwd_4.0.13-7ubuntu3.1_powerpc.deb
Size/MD5: 664842 5563779a731a87712744f8107c015d9b

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/poo...dow/login_4.0.13-7ubuntu3.1_sparc.deb
Size/MD5: 239766 e3f275f96e8425f70460dcf9db1f00c2
http://security.ubuntu.com/ubuntu/poo...ow/passwd_4.0.13-7ubuntu3.1_sparc.deb
Size/MD5: 619800 92f7fe2c32a62fa4517b7cc89c497dfc

Changelog:
2006-07-12: Added CVE reference.

Original Advisory:
http://www.ubuntu.com/usn/usn-308-1

Other References:
SA20950:
http://secunia.com/advisories/20950/



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

456 Related Secunia Security Advisories, displaying 10

1. Ubuntu update for php
2. Ubuntu update for firefox
3. Ubuntu update for kernel
4. Ubuntu update for bind
5. Ubuntu update for pcre3
6. Ubuntu update for firefox
7. Ubuntu update for ruby1.8
8. Ubuntu update for kernel
9. Ubuntu update for samba
10. Ubuntu update for xorg-server

Show all related advisories


Send Feedback to Secunia

If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
OpenBSD BIND Query Port DNS Cache Poisoning
2.
Ubuntu update for php
3.
Linux Kernel LDT Buffer Size Handling Vulnerability
4.
Drupal Session Fixation Vulnerability
5.
Red Hat update for kernel
6.
Slackware update for dnsmasq
7.
IPCop update for perl
8.
Fedora update for asterisk
9.
Red Hat update for thunderbird
10.
Debian update for xulrunner





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia