Bug Fix Advisory Updated shadow-utils package

Advisory: RHBA-2004:527-03
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2004-12-13
Last updated on: 2004-12-13
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A

Details

An updated shadow-utils package that fixes locking in useradd is now
available.

The shadow-utils package includes the necessary programs for converting
UNIX password files to the shadow password format, as well as programs for
managing user and group accounts. The pwconv command converts passwords to
the shadow password format. The pwunconv command unconverts shadow
passwords and generates an npasswd file (a standard UNIX password file).
The pwck command checks the integrity of password and shadow files. The
lastlog command prints out the last login times for all users. The useradd,
userdel, and usermod commands are used for managing user accounts. The
groupadd, groupdel, and groupmod commands are used for managing group accounts.

The useradd command did not properly unlock the user and group database
files on exit. This has been fixed.

All users of shadow-utils should upgrade to this updated package, which
resolves the issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
shadow-utils-20000902-17.src.rpm     3f37118a75cf9b4dfbae412a512f4554
 
IA-32:
shadow-utils-20000902-17.i386.rpm     50abdb5a9e3d0f778d3ded769d0ebccb
 
IA-64:
shadow-utils-20000902-17.ia64.rpm     0014b417e8574961782fd9d72b38102e
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
shadow-utils-20000902-17.src.rpm     3f37118a75cf9b4dfbae412a512f4554
 
IA-32:
shadow-utils-20000902-17.i386.rpm     50abdb5a9e3d0f778d3ded769d0ebccb
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
shadow-utils-20000902-17.src.rpm     3f37118a75cf9b4dfbae412a512f4554
 
IA-32:
shadow-utils-20000902-17.i386.rpm     50abdb5a9e3d0f778d3ded769d0ebccb
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
shadow-utils-20000902-17.src.rpm     3f37118a75cf9b4dfbae412a512f4554
 
IA-64:
shadow-utils-20000902-17.ia64.rpm     0014b417e8574961782fd9d72b38102e
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

126709 - [PATCH]passwd.lock and group.lock file is never removed after using the command useradd



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/