Shadow: Privilege escalation — GLSA 202008-09

Multiple Shadow utilities were installed with setuid permissions, allowing possible root privilege escalation.

Affected packages

sys-apps/shadow on all architectures
Affected versions < 4.8-r3
Unaffected versions >= 4.8-r3

Background

Shadow is a set of tools to deal with user accounts.

Description

When Shadow was installed with the PAM use flag, setuid binaries provided by Shadow were not properly restricted.

Impact

A local attacker could escalate privileges to root.

Workaround

There is no known workaround at this time.

Resolution

All Shadow users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.8-r3"
 

References

Release date
August 25, 2020

Latest revision
August 25, 2020: 1

Severity
high

Exploitable
local

Bugzilla entries