-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 07 Apr 2025 12:38:46 +0200 Source: shadow Binary: libsubid-dev libsubid4 libsubid4-dbgsym login login-dbgsym passwd passwd-dbgsym uidmap uidmap-dbgsym Architecture: armhf Version: 1:4.13+dfsg1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Chris Hofstaedtler Description: libsubid-dev - subordinate id handling library -- shared library libsubid4 - subordinate id handling library -- shared library login - system login tools passwd - change and administer password and group data uidmap - programs to help use subuids Closes: 1034482 1051062 Changes: shadow (1:4.13+dfsg1-1+deb12u1) bookworm; urgency=medium . [ Balint Reczey ] * Cherry-pick upstream patch to fix gpasswd passwd leak (Closes: #1051062) CVE-2023-4641 * Cherry-pick upstream patch to fix chfn vulnerability (Closes: #1034482) CVE-2023-29383 * Fix valid_field() that regressed in upstream's chfn fix . [ Chris Hofstaedtler ] * Update Uploaders: field from unstable Checksums-Sha1: c95d6edd22f4384bb44f3fc42d72cf0460956081 220236 libsubid-dev_4.13+dfsg1-1+deb12u1_armhf.deb ebc4c97138d7221719e94309d091a4706146295e 169540 libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb ead565b81dcc1c8ae2e7080fdb25b39e374c561e 201752 libsubid4_4.13+dfsg1-1+deb12u1_armhf.deb 2075ce0d9100a7bfc3b4541d48afa7027b5f066d 123404 login-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 2c3813d0aa4f439a64b5b2aec6945f66938b96e4 612196 login_4.13+dfsg1-1+deb12u1_armhf.deb b0e18777eeedaff792038995cd40bceb4132937b 1420408 passwd-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 1f6aa4aa76e3f187792e621cf60cb9e1134e8a91 922488 passwd_4.13+dfsg1-1+deb12u1_armhf.deb bc5f99523af71395debb35175677c3a1975c645f 9369 shadow_4.13+dfsg1-1+deb12u1_armhf-buildd.buildinfo f45d5c9f1b061207cc61c8a1e8c693fcb5c04083 102968 uidmap-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb c1584a53550d3583e6eb0ffbdfa1d23918942371 184376 uidmap_4.13+dfsg1-1+deb12u1_armhf.deb Checksums-Sha256: 8529223440f37314d70246f24d8abe4dac46e34d6780c26b043dba7be68edee4 220236 libsubid-dev_4.13+dfsg1-1+deb12u1_armhf.deb 37b88780f5a91b5b3dc323bb9b3d85fd64e692ae7e1b2586342891887dbbbed9 169540 libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb dcf9a60714f06be66717658f5c657770b4c2fb69fa3f4ed3b4ceaa18025c811a 201752 libsubid4_4.13+dfsg1-1+deb12u1_armhf.deb ca31b738929b1de8238770ba0bd9531aad255751cdcd51baa692ae6899c06551 123404 login-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 0da9ad693b329925f38393efe595ba37544e197d1e3069f1f604cc8f9b1311fa 612196 login_4.13+dfsg1-1+deb12u1_armhf.deb 7a13251638267e1702ac5dfb7edaa8fa0ca1164159a3ab2ace2da1f011769d7d 1420408 passwd-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 545925825e4d38fbad6a1b5bba0899907f04031ee402d4379bff88403a0e9b9c 922488 passwd_4.13+dfsg1-1+deb12u1_armhf.deb f87290cf96d46033012d56008206553a0326ee8ecebeb297faee5e8de8d3b8c5 9369 shadow_4.13+dfsg1-1+deb12u1_armhf-buildd.buildinfo bfbb4dd13b1302f581f84f7d61dfad1a5f68483aea7504335a58c1587290f6c8 102968 uidmap-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 576c668faac0637c32fc786c2236ef64d1a2a82ef5d0c53a2d47799aefbd37f1 184376 uidmap_4.13+dfsg1-1+deb12u1_armhf.deb Files: 5f40eb6d5e20a0975071eed9f6236ed9 220236 libdevel optional libsubid-dev_4.13+dfsg1-1+deb12u1_armhf.deb 7ac66ec647ce6c095d9bccd0570a4387 169540 debug optional libsubid4-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 9186a3296673fb123c81e92bf942c290 201752 libs optional libsubid4_4.13+dfsg1-1+deb12u1_armhf.deb 2820fd7b4f1e165f4208bc2743d4e111 123404 debug optional login-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 6be012bc43b33d0f002fb2c5a0bac7e1 612196 admin required login_4.13+dfsg1-1+deb12u1_armhf.deb b6d13ebcf973e65fe56b2eb43cb7126e 1420408 debug optional passwd-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 4347a1fed689e8c638a0cc7a9b5e6b0b 922488 admin required passwd_4.13+dfsg1-1+deb12u1_armhf.deb 51e50032fa782f632997f8c458b27d80 9369 admin required shadow_4.13+dfsg1-1+deb12u1_armhf-buildd.buildinfo 7867a70597e69a5d79b5ee8bcfae439b 102968 debug optional uidmap-dbgsym_4.13+dfsg1-1+deb12u1_armhf.deb 69ea95e89b2c2641b7f3ed37cc3f900e 184376 admin optional uidmap_4.13+dfsg1-1+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErcTbumGV7Ig2iXlfQdxRZ9J7nEgFAmgfj0cACgkQQdxRZ9J7 nEh5Bg//bqveYbTT/Qi1KeY2uxsjiz54y/GXe84Rn+TXdfv2bH5gCJ6I5Cdti1TV 8LfKRrDmLUN16k/30ezaejS7ISnrP1YspxcnPy64IhFmhOY4NNsS4LqYT8u8dhyP OPWCBBARKqMOt3UEn3emgHd+Ef6zuMySnSARPrmOykbf9f89PK+q4RN4ayMjW8Th cyrO3jcxJHsiaLCcX0wNkwG2wHIA+0fNAjHaOxPOUAQkkjI10MDAPG1PlsbQU1I3 XOnOZZB0sYkdeTlGw9HgUmWa9fSE4WeN0Aqw38Rtnzyj6+QxIi23NQtgMic/XQa7 wD+/DX43AGeneGo8MF7URE0ajhGFdG+bwXU1a1Mtr13quzZbJXsqrroGP0xoSOou J0ke5haADIj4ItyIhd/5wtogbwMn2bdS5A/r3X36BT7pTRMBggOuDDJNywDJpNJV C1oP7twKP7oPx0HcRz3+IncX0Zoaiy5Rvk4ggZLzLpmmm7Yjm+VYFVkTMdvcjJzp FhIjG9e8VhAj8VYA58TrcoZezROSz0D+nnUNzoEekFhtHnQjPQ5mu82pm9d5LWI5 MzdvxIL7L13IPmJpi5r3vSf0z0V7v/3EoB3Dv67KEUthtmSBDxt5FtbDpjoRA9vl 9yKQcucNqglQE7TxdqIQwoavEnEgYvwghZkPGRWUhvBBdiTO9z8= =ZeU2 -----END PGP SIGNATURE-----