-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 07 Apr 2025 12:38:46 +0200 Source: shadow Architecture: source Version: 1:4.13+dfsg1-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: Shadow package maintainers Changed-By: Chris Hofstaedtler Closes: 1034482 1051062 Changes: shadow (1:4.13+dfsg1-1+deb12u1) bookworm; urgency=medium . [ Balint Reczey ] * Cherry-pick upstream patch to fix gpasswd passwd leak (Closes: #1051062) CVE-2023-4641 * Cherry-pick upstream patch to fix chfn vulnerability (Closes: #1034482) CVE-2023-29383 * Fix valid_field() that regressed in upstream's chfn fix . [ Chris Hofstaedtler ] * Update Uploaders: field from unstable Checksums-Sha1: a587852839e5271f4a0b2811cb6cde9ca87dd5fc 2433 shadow_4.13+dfsg1-1+deb12u1.dsc 2cc855dc07c130a40bfaa121464f4d9d4a8b81f9 82088 shadow_4.13+dfsg1-1+deb12u1.debian.tar.xz 06d184ddaf9ae50239fd88b8834b8d2d69fcf78f 9961 shadow_4.13+dfsg1-1+deb12u1_arm64.buildinfo Checksums-Sha256: 8045717c55c3e19402da41b9223f6e2148e89de66b10210be5ab556b34d85b23 2433 shadow_4.13+dfsg1-1+deb12u1.dsc 12dfb1a9b824855db5bd5dd731ab0633b274b5fae1cdac8a114359415adf7d31 82088 shadow_4.13+dfsg1-1+deb12u1.debian.tar.xz 986f672aa8fc8cf0eead9a4c9cf26d83701fe67aa30f965ddeb7cbdea705326c 9961 shadow_4.13+dfsg1-1+deb12u1_arm64.buildinfo Files: 119c9fa0bf8013d7317c749e09db3206 2433 admin required shadow_4.13+dfsg1-1+deb12u1.dsc 3242b2f9362a28ee84a861316ba85d08 82088 admin required shadow_4.13+dfsg1-1+deb12u1.debian.tar.xz 434753606b4a6fc22e0b5081cef1ad3d 9961 admin required shadow_4.13+dfsg1-1+deb12u1_arm64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmgfc6AACgkQXBPW25MF LgMHkg/9HpwSZyP1zFrpram6QWqPi5yEIGSDoA5glIhTuq0fgwfBTcP1GsxcahuR AoOsIjS1vdbGn9I3y6TLS460kEHCahpO0w5g+iC4LMBiMO7QDcChD2wB1TzDQd8K A4FYLRpxn0liDeDUfH1nHIupfMk1s9P7lGLLZgM5+lqYlDXF7b+slKhhJpc+G1sM ViVkD1BfI+iUW13i4I38mjlBaNq96zrcZezR2JQCE7llPrM2k49r6fbIpyC3I7+6 E7JSsRvrI/OwKFnofqmta7E2Ayj5dNWH7Ihlc7iFxV2IeyLSqehQPwDp1IEAS0lX G1KkMbAUNmIw8EQzjUQiha8hZ0+ag7xC4rroJsL+5xZjXgI5dhlOHBG9E/jbz+sN LBe5HZGGIpWOnZAt38xXvqjZOgMjLkjj07oF3DdR6qsQlLkHqy6rfUnDqRlSOtrd x0zzZEcbh0WhJcpBI8f0ePs9g45MtG7O5P3R7XlQ5ubSNqU4zP1uZg5O+0uQaa53 I0c2zIoXBeudMrphjiQZPUnd3txDy8GUzw2YmNSM3jw+GsOhpiCup536RWWyF1SE KNIIaqDOwbyJzJBpWiZw1u02X6iFpqBZYk8sPEYzTJjpdESz+9Jg9yS1rvDqrGxu ZIBU+endyf6RkhSb4+irpVr5DQzvjN4uazXegZ51BXUOdFp1DCU= =HkzT -----END PGP SIGNATURE-----