Bug Fix Advisory shadow-utils bug fix update

Advisory: RHBA-2008:0866-3
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2008-09-03
Last updated on: 2008-09-03
Affected Products: Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
OVAL: N/A

Details

An updated shadow-utils package that fixes a bug is now available.

The shadow-utils package includes the necessary programs for converting
UNIX® password files to the shadow password format, as well as tools for
managing user and group accounts.

This updated shadow-utils package fixes a bug in which, when using either
the 'useradd' or 'usermod' commands, a simple typo resulted in the user
that was being added or modified to be added to the root group, even if
the root group was not specified with the 'useradd' or 'usermod' commands.

All users of shadow-utils are advised to upgrade to this updated package,
which resolves this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Enterprise Linux (v. 5 server)

SRPMS:
shadow-utils-4.0.17-14.el5.src.rpm     f986f03838e600f6eacb744b51bc4aec
 
IA-32:
shadow-utils-4.0.17-14.el5.i386.rpm     1bb4cb7465e5b01d8c27301caf563731
 
IA-64:
shadow-utils-4.0.17-14.el5.ia64.rpm     49b6aa30269214e0216b0a3c600b8db5
 
PPC:
shadow-utils-4.0.17-14.el5.ppc.rpm     44fe7a18dbaffda6203cfa5b78e6f852
 
s390x:
shadow-utils-4.0.17-14.el5.s390x.rpm     89b84f3ebd8ac242266bd78301e0df19
 
x86_64:
shadow-utils-4.0.17-14.el5.x86_64.rpm     803582df52fe3deb72ff8d71163d145f
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
shadow-utils-4.0.17-14.el5.src.rpm     f986f03838e600f6eacb744b51bc4aec
 
IA-32:
shadow-utils-4.0.17-14.el5.i386.rpm     1bb4cb7465e5b01d8c27301caf563731
 
x86_64:
shadow-utils-4.0.17-14.el5.x86_64.rpm     803582df52fe3deb72ff8d71163d145f
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

450262 - usermod/useradd may inadvertently give access to group root



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/