Shadow: security bypass A vulnerability found in Shadow may allow local attackers to bypass security restrictions. shadow 2018-05-22 2018-05-22 647790 remote 4.6 4.6

Shadow is a set of tools to deal with user accounts.

A local attacker could possibly bypass security restrictions if an administrator used “group blacklisting” to restrict access to file system paths.

A local attacker could possibly bypass security restrictions.

There is no known workaround at this time.

All shadow users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.6"
CVE-2018-7169 Zlogene Zlogene