ELA-1395-1 shadow security update

multiple vulnerabilities

2025-04-15
Packageshadow
Version1:4.2-3+deb8u6 (jessie)
Related CVEs CVE-2023-4641 CVE-2023-29383


Several vulnerabilities were discovered in the shadow suite of login tools. An attacker may extract a password from memory in limited situations, and confuse an administrator inspecting /etc/passwd from within a terminal.



For Debian 8 jessie, these problems have been fixed in version 1:4.2-3+deb8u6.

We recommend that you upgrade your shadow packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.