GLSA 202210-26: Shadow: TOCTOU Race

Severity:normal
Title:Shadow: TOCTOU Race
Date:10/31/2022
Bugs: #830486
ID:202210-26

Synopsis

A TOCTOU race has been discovered in Shadow, which could result in the unauthorized modification of files.

Background

Shadow contains utilities to deal with user accounts

Affected packages

Package Vulnerable Unaffected Architecture(s)
sys-apps/shadow < 4.12.2 >= 4.12.2 All supported architectures

Description

A TOCTOU race condition was discovered in shadow. A local attacker with write privileges in a directory removed or copied by usermod/userdel could potentially exploit this flaw when the administrator invokes usermod/userdel.

Impact

An unauthorized user could potentially modify files which they do not have write permissions for.

Workaround

There is no known workaround at this time.

Resolution

All Shadow users should upgrade to the latest version:

          # emerge --sync
          # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.12.2"
        

References

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-202210-26.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

License

Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

Thank you!