QID 356977

Date Published: 2024-01-17

QID 356977: Amazon Linux Security Advisory for shadow-utils : AL2012-2023-461

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-4641:
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 356977

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2023-461 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html