Bug 6910 - [Anolis OS 23] Bugfix for CVE-2023-4641
Summary: [Anolis OS 23] Bugfix for CVE-2023-4641
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P4-Low S4-trivial
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-10-18 15:35 UTC by 小龙
Modified: 2023-10-18 15:35 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-10-18 15:35:15 UTC
Description:
在Shadow-utils中发现了一个缺陷。当要求输入新密码时,shadow-utils会询问密码两次。如果第二次尝试密码失败,shadow-utils无法清理用于存储第一个条目的缓冲区。这可能允许具有足够访问权限的攻击者从内存中检索密码。

Broken commit info:

Bugfix commit info:
https://github.com/shadow-maint/shadow/commit/65c88a43a23c2391dcc90c0abda3e839e9c57904