Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Back to bug 702252

Who When What Removed Added
jer 2019-12-07 20:47:54 UTC Product Gentoo Linux Gentoo Security
Component Current packages Auditing
Assignee bug-wranglers security-audit
Severity major normal
jer 2019-12-07 20:48:25 UTC CC base-system
polynomial-c 2019-12-08 12:22:02 UTC Ever confirmed 0 1
Status UNCONFIRMED CONFIRMED
polynomial-c 2019-12-17 09:29:16 UTC Status CONFIRMED IN_PROGRESS
repo-qa-checks 2019-12-17 21:04:09 UTC See Also https://github.com/gentoo/gentoo/pull/14032
Keywords PullRequest
polynomial-c 2019-12-18 20:30:53 UTC Alias CVE-2019-19882
Assignee security-audit security
Summary sys-apps/shadow-4.8-r1[pam] installs setuid binaries with permissive pam configuration allowing user/group management without authentication sys-apps/shadow-4.8-r1[pam] installs setuid binaries with permissive pam configuration allowing user/group management without authentication (CVE-2019-19882)
Component Auditing Vulnerabilities
polynomial-c 2019-12-18 20:31:19 UTC Keywords PullRequest
zlogene 2020-03-07 19:06:03 UTC Whiteboard B2 [stable cve]
Package list sys-apps/shadow-4.8-r3
CC amd64, arm64, arm, hppa, ia64, m68k, ppc64, ppc, s390, sh, sparc, x86
Summary sys-apps/shadow-4.8-r1[pam] installs setuid binaries with permissive pam configuration allowing user/group management without authentication (CVE-2019-19882) <sys-apps/shadow-4.8-r3[pam] installs setuid binaries with permissive pam configuration allowing user/group management without authentication (CVE-2019-19882)
stable-bot 2020-03-07 20:01:09 UTC Flags sanity-check+
ago 2020-03-08 09:56:51 UTC CC s390
zlogene 2020-03-08 10:21:30 UTC CC amd64
ago 2020-03-08 10:24:04 UTC CC sparc
ago 2020-03-08 10:25:45 UTC CC arm
ago 2020-03-08 11:11:24 UTC CC ppc
ago 2020-03-08 12:13:04 UTC CC x86
ago 2020-03-08 12:34:38 UTC CC ia64
ago 2020-03-08 12:35:42 UTC CC ppc64
polynomial-c 2020-03-13 14:36:37 UTC See Also https://bugs.gentoo.org/show_bug.cgi?id=712372
polynomial-c 2020-03-16 18:25:55 UTC Package list sys-apps/shadow-4.8-r3 sys-apps/shadow-4.8-r4
leio 2020-03-17 10:18:00 UTC CC arm64
eike 2020-03-18 18:20:56 UTC CC hppa
zlogene 2020-03-26 14:07:38 UTC CC sh
slyfox 2020-04-21 07:48:34 UTC CC m68k
sam 2020-04-21 07:52:02 UTC Whiteboard B2 [stable cve] B2 [cleanup glsa cve]
sam 2020-04-21 08:25:57 UTC Whiteboard B2 [cleanup glsa cve] B2 [glsa cve]
nattka 2020-08-21 08:09:43 UTC Flags sanity-check+ sanity-check-
glsamaker 2020-08-25 12:54:29 UTC Resolution --- FIXED
Whiteboard B2 [glsa cve] B2 [glsa+ cve]
Status IN_PROGRESS RESOLVED
joakim.tjernlund 2020-09-15 09:17:16 UTC CC joakim.tjernlund
sam 2023-02-17 01:49:15 UTC See Also https://bugs.gentoo.org/show_bug.cgi?id=894998

Back to bug 702252