Debian update for mod_auth_shadow
Secunia Advisory: SA10613
Release Date: 2004-01-13
Popularity: 6,209 views

Critical:
Not critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2004-0041


Description:
Debian has issued updated packages for mod_auth_shadow. These fix a security issue allowing expired accounts to authenticate.

For more information:
SA10612

Solution:
Updated packages:

Debian GNU/Linux 3.0 alias woody

Source archives:

http://security.debian.org/pool/updat...ow/mod-auth-shadow_1.3-3.1woody.1.dsc
Size/MD5 checksum: 628 0631b85270f5e589909ce3618976bffe
http://security.debian.org/pool/updat...od-auth-shadow_1.3-3.1woody.1.diff.gz
Size/MD5 checksum: 5453 b5f344fb69005ca149bacf286844832f
http://security.debian.org/pool/updat...hadow/mod-auth-shadow_1.3.orig.tar.gz
Size/MD5 checksum: 7476 3ad4432193ac603049ad0f2fa94f2054

Alpha architecture:

http://security.debian.org/pool/updat...-auth-shadow_1.3-3.1woody.1_alpha.deb
Size/MD5 checksum: 11970 d73f8c7bbc56f603aff27c9e0839c685

ARM architecture:

http://security.debian.org/pool/updat...od-auth-shadow_1.3-3.1woody.1_arm.deb
Size/MD5 checksum: 11064 a016baa2812a950e0daed4930e06064a

Intel IA-32 architecture:

http://security.debian.org/pool/updat...d-auth-shadow_1.3-3.1woody.1_i386.deb
Size/MD5 checksum: 11116 37050a0429d599a878f52a78f64c53a1

Intel IA-64 architecture:

http://security.debian.org/pool/updat...d-auth-shadow_1.3-3.1woody.1_ia64.deb
Size/MD5 checksum: 13230 12e15d476e2923212066955329572fc8

HP Precision architecture:

http://security.debian.org/pool/updat...d-auth-shadow_1.3-3.1woody.1_hppa.deb
Size/MD5 checksum: 11810 dc63de9f64595d784f76b7ba4a42f19b

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...d-auth-shadow_1.3-3.1woody.1_m68k.deb
Size/MD5 checksum: 11078 f2e0f2c0a0fac24061d9043749c1d4da

Big endian MIPS architecture:

http://security.debian.org/pool/updat...d-auth-shadow_1.3-3.1woody.1_mips.deb
Size/MD5 checksum: 11230 2ddbceff8f93ad432e090b634244c4f5

Little endian MIPS architecture:

http://security.debian.org/pool/updat...auth-shadow_1.3-3.1woody.1_mipsel.deb
Size/MD5 checksum: 11232 55320be2e6212242eb00310716ae346a

PowerPC architecture:

http://security.debian.org/pool/updat...uth-shadow_1.3-3.1woody.1_powerpc.deb
Size/MD5 checksum: 11122 2ee5de78bdd4112d53be7416185fcc64

IBM S/390 architecture:

http://security.debian.org/pool/updat...d-auth-shadow_1.3-3.1woody.1_s390.deb
Size/MD5 checksum: 11262 1d3b72a731147bb7b59255844036f024

Sun Sparc architecture:

http://security.debian.org/pool/updat...-auth-shadow_1.3-3.1woody.1_sparc.deb
Size/MD5 checksum: 14240 cbe2bc47536b40fa46c8eb400a8b7db1

Debian GNU/Linux unstable alias sid
This is fixed in version 1.4-1.

Original Advisory:
http://lists.debian.org/debian-securi...-security-announce-2004/msg00015.html

Other References:
SA10612:
http://secunia.com/advisories/10612/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB "gen_rand_string()" Predictable RNG Weakness // 89 views
2. Adobe Flash Player Multiple Vulnerabilities // 78 views
3. Sun Java JDK / JRE Multiple Vulnerabilities // 39 views
4. VLC Media Player Multiple Vulnerabilities // 35 views
5. IBM DB2 Multiple Vulnerabilities // 35 views
6. Microsoft Office Two Code Execution Vulnerabilities // 28 views
7. Microsoft Word Malformed Object Pointer Vulnerability // 27 views
8. libpng "png_push_read_zTXt()" Off-By-One Vulnerability // 27 views
9. Linux Kernel "listxattr" Memory Corruption and CHRP Denial of Service // 27 views
10. Silentum LoginSys Multiple Cross-site Scripting Vulnerabilities // 25 views