Debian 10417 Published by

Debian GNU/Linux has been updated with two security patches for Shadow and PostgreSQL:

Debian GNU/Linux 10 (Buster) Extended LTS:
ELA-1398-1 postgresql-11 security update

Debian GNU/Linux 11 (Bullseye) LTS:
[DLA 4130-1] shadow security update





[SECURITY] [DLA 4130-1] shadow security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4130-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Sylvain Beucler
April 18, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : shadow
Version : 1:4.8.1-1+deb11u1
CVE ID : CVE-2023-4641 CVE-2023-29383
Debian Bug : 1034482 1051062

Several vulnerabilities were discovered in the shadow suite of login
tools. An attacker may extract a password from memory in limited
situations, and confuse an administrator inspecting /etc/passwd from
within a terminal.

CVE-2023-4641

When asking for a new password, shadow-utils asks the password
twice. If the password fails on the second attempt, shadow-utils
fails in cleaning the buffer used to store the first entry. This
may allow an attacker with enough access to retrieve the password
from the memory.

CVE-2023-29383

It is possible to inject control characters into fields provided
to the SUID program chfn (change finger). Although it is not
possible to exploit this directly (e.g., adding a new user fails
because \n is in the block list), it is possible to misrepresent
the /etc/passwd file when viewed.

For Debian 11 bullseye, these problems have been fixed in version
1:4.8.1-1+deb11u1.

We recommend that you upgrade your shadow packages.

For the detailed security status of shadow please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/shadow

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



ELA-1398-1 postgresql-11 security update


Package : postgresql-11
Version : 11.22-0+deb10u5 (buster)

Related CVEs :
CVE-2025-1094

PostgreSQL, a popular database, was affected by a vulnerability.
Improper neutralization of quoting syntax in PostgreSQL libpq functions
PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and
PQescapeStringConn() allows a database input provider to achieve
SQL injection in certain usage patterns.


ELA-1398-1 postgresql-11 security update