SB2017022503 - Race condition in shadow (Alpine package)
Published: February 25, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2017-2616)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to race condition within shadow-utils implementation. A local user can kill other processes on the system with root privileges.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=268b69b781cc266d5eaafc5b4fd4a2ca9d54c2d9
- https://git.alpinelinux.org/aports/commit/?id=fe20e8da2f8b7fb6f208cccf8f369400d947a6a2
- https://git.alpinelinux.org/aports/commit/?id=e626ce8c3c4d65d1a587ebfe27166755c699bb8c
- https://git.alpinelinux.org/aports/commit/?id=27e745e6b16e354f98de885984bee4ccce9e03b0
- https://git.alpinelinux.org/aports/commit/?id=e9a92d060e2e59ac087373af9b81546c2a761d07
- https://git.alpinelinux.org/aports/commit/?id=0d87734696c2c04083fae90ef045d87926d35ebd