Re: [OE-core] [PATCH 1/1] shadow: fix CVE-2017-12424

2017-08-21 Thread Randy MacLeod
On 2017-08-18 04:20 PM, Randy MacLeod wrote: On 2017-08-16 07:34 AM, Jussi Kukkonen wrote: On 16 August 2017 at 13:28, Chen Qi > wrote: Backport a patch to fix CVE-2017-12424. In shadow before 4.5, the newusers tool could be made

Re: [OE-core] [PATCH 1/1] shadow: fix CVE-2017-12424

2017-08-18 Thread Randy MacLeod
On 2017-08-16 07:34 AM, Jussi Kukkonen wrote: On 16 August 2017 at 13:28, Chen Qi > wrote: Backport a patch to fix CVE-2017-12424. In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in

Re: [OE-core] [PATCH 1/1] shadow: fix CVE-2017-12424

2017-08-16 Thread Jussi Kukkonen
On 16 August 2017 at 13:28, Chen Qi wrote: > Backport a patch to fix CVE-2017-12424. > > In shadow before 4.5, the newusers tool could be made to manipulate > internal data structures in ways unintended by the authors. > > Reference link:

[OE-core] [PATCH 1/1] shadow: fix CVE-2017-12424

2017-08-16 Thread Chen Qi
Backport a patch to fix CVE-2017-12424. In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Reference link: https://nvd.nist.gov/vuln/detail/CVE-2017-12424 CVE: CVE-2017-12424 Signed-off-by: Chen Qi