CVE-2023-4641: Shadow-utils: possible password leak during passwd(1) change
Published Jun 19, 2023
·Updated
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Affected Software
29 affected componentsFixes available
debian/shadow<=1:4.5-1.1, <=1:4.8.1-1, <=1:4.13+dfsg1-1
1:4.13+dfsg1-4
ubuntu/shadow<1:4.5-1ubuntu2.5+
1:4.5-1ubuntu2.5+
ubuntu/shadow<1:4.8.1-1ubuntu5.20.04.5
1:4.8.1-1ubuntu5.20.04.5
ubuntu/shadow<1:4.8.1-2ubuntu2.2
1:4.8.1-2ubuntu2.2
ubuntu/shadow<1:4.13+dfsg1-1ubuntu1.1
1:4.13+dfsg1-1ubuntu1.1
ubuntu/shadow<1:4.1.5.1-1ubuntu9.5+
1:4.1.5.1-1ubuntu9.5+
ubuntu/shadow<1:4.13+dfsg1-2, <4.14.0
1:4.13+dfsg1-24.14.0
ubuntu/shadow<1:4.2-3.1ubuntu5.5+
1:4.2-3.1ubuntu5.5+
redhat/shadow-utils<4.14.0
4.14.0
shadow-maint shadow-utils<4.14.0
redhat Codeready Linux Builder=8.0
redhat Codeready Linux Builder=9.0
redhat Codeready Linux Builder For Arm64=8.0_aarch64
redhat Codeready Linux Builder For Arm64=9.0_aarch64
redhat Codeready Linux Builder For Ibm Z Systems=8.0_s390x
redhat Codeready Linux Builder For Ibm Z Systems=9.0_s390x
redhat Codeready Linux Builder For Power Little Endian=8.0_ppc64le
redhat Codeready Linux Builder For Power Little Endian=9.0_ppc64le
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux For Arm 64=8.0
redhat Enterprise Linux For Arm 64=9.0
redhat Enterprise Linux For Ibm Z Systems=8.0_s390x
redhat Enterprise Linux For Ibm Z Systems=9.0_s390x
redhat Enterprise Linux For Power Little Endian=8.0_ppc64le
redhat Enterprise Linux For Power Little Endian=9.0_ppc64le
IBM R10.0<=10.1.3.0
10.0.245.0
IBM R9.4<=89.42.18.0
89.41.25.0
89.40.83.0
IBM R9.3<=89.33.52.0
89.33.45.0
Remediation
Event History
Dec 27, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 15, 2024
Data Sourced
via Launchpad·06:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-4641?
CVE-2023-4641 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-4641?
To fix CVE-2023-4641, update shadow-utils to version 1:4.13+dfsg1-4 or higher.
3
What impact does CVE-2023-4641 have on affected systems?
CVE-2023-4641 can potentially allow attackers to retrieve sensitive passwords from memory.
4
Which versions of shadow-utils are affected by CVE-2023-4641?
Versions of shadow-utils up to 4.14.0 are affected by CVE-2023-4641.
5
What operating systems are impacted by CVE-2023-4641?
CVE-2023-4641 affects multiple versions of Debian and Ubuntu operating systems.