Commit Graph

891 Commits

Author SHA1 Message Date
Sylvain Beucler 7f6e0ec904 Import Debian changes 1:4.8.1-1+deb11u1
shadow (1:4.8.1-1+deb11u1) bullseye-security; urgency=high
.
  * Non-maintainer upload by the LTS Security Team.
  * CVE-2023-4641: When asking for a new password, shadow-utils asks the
    password twice. If the password fails on the second attempt,
    shadow-utils fails in cleaning the buffer used to store the first
    entry. This may allow an attacker with enough access to retrieve the
    password from the memory. (Closes: #1051062)
  * CVE-2023-29383: It is possible to inject control characters into
    fields provided to the SUID program chfn (change finger). Although it
    is not possible to exploit this directly (e.g., adding a new user
    fails because \n is in the block list), it is possible to misrepresent
    the /etc/passwd file when viewed. (Closes: #1034482)
  * Add Salsa-CI configuration.
  * Silence lintian error that can't be fixed after freeze.
debian/1%4.8.1-1+deb11u1
2025-04-18 17:29:39 +02:00
Balint Reczey 7456cef7e2 Update changelog debian/1%4.8.1-1 2020-02-07 15:54:36 +01:00
Balint Reczey dc0f840741 debian/HOME_MODE.xml: Ship the file that was accidentally omitted from upstream tarball 2020-02-07 00:22:41 +01:00
Balint Reczey 10af5ab4c4 Update changelog 2020-02-07 00:10:01 +01:00
Balint Reczey 2d2f190b5f Refresh patches 2020-02-06 23:33:56 +01:00
Balint Reczey 8b9729cf03 Update upstream source from tag 'upstream/4.8.1'
Update to upstream version '4.8.1'
with Debian dir 4e0ff7ffe2
2020-02-06 23:15:01 +01:00
Balint Reczey d906ecd3b6 New upstream version 4.8.1 upstream/4.8.1 2020-02-06 23:14:47 +01:00
Balint Reczey 8a1d6c51aa debian/default/useradd: Fix typo DHSELL -> DSHELL
Closes: #897028
2019-12-27 22:44:17 +01:00
Balint Reczey b1eaec13e7 Update changelog debian/1%4.8-1 2019-12-20 16:40:45 +01:00
Balint Reczey 262a350c14 debian/login.su.pam: Drop unused file 2019-12-16 23:02:27 +01:00
Andreas Henriksson 752c64e4e4 Update debian/changelog 2019-12-05 15:17:06 +01:00
Andreas Henriksson fa4dccbc4a Fix lintian warning useless-autoreconf-build-depends
Newer debhelper will pull in and run dh-autoreconf
by default, so no need for explicit build-depends or
usage.
2019-12-05 15:17:06 +01:00
Andreas Henriksson e34706dd5b Cherry-pick upstream patch reverting bindir/sbindir
From:
https://github.com/shadow-maint/shadow/commit/3cc3948d719d3b9dedaaf2e96221e4b5b96ea380.patch
2019-12-05 15:12:17 +01:00
Andreas Henriksson 787ebc3336 Refresh and massage patches to apply
The following needed massaging to apply:
* debian/patches/508_nologin_in_usr_sbin
* debian/patches/401_cppw_src.dpatch

The remaining patches just got trivial quilt refresh updates,
except debian/patches/506_relaxed_usernames which needed
special attention to be correctly refreshed.
2019-12-05 15:08:29 +01:00
Andreas Henriksson 93ea3fe510 Use explicit --without-su configure flag
The shadow package did now ship the su program even before this,
Debian uses the util-linux implementation of su (since Buster).
In shadow 4.8 there's now an explicit configure flag that can be
used to disable su explicitly, rather than just not shipping it in
the resulting debian package.

See commit 88de51965d
"Stop shipping su and break old util-linux version. (See #833256)"
2019-12-05 13:39:26 +01:00
Andreas Henriksson 30e6a960ee Replace gnome-doc-utils build-dep with itstool
Closes: #881889
2019-12-05 13:34:19 +01:00
Andreas Henriksson e38381641b Update debian/changelog 2019-12-05 13:34:19 +01:00
Andreas Henriksson 69d932140c New upstream version 4.8 upstream/4.8 2019-12-05 13:29:31 +01:00
Andreas Henriksson dc46a7a96f Update upstream source from tag 'upstream/4.8'
Update to upstream version '4.8'
with Debian dir 22c83fa39e
2019-12-05 13:29:31 +01:00
Andreas Henriksson 1177f4b257 Update debian/changelog 2019-12-05 13:29:18 +01:00
Yuriy M. Kaminskiy 0a3492dd90 Mark uidmap and login as Multi-Arch: foreign
Closes: #934473
2019-11-11 16:54:57 +01:00
Justin B Rye 77901f4115 login: Update package description
Closes: #808301
2019-11-11 16:25:49 +01:00
Balint Reczey 042e76175a Merge branch 'pam_selinux' into 'master'
Move the call to pam_motd before pam_selinux open

See merge request debian/shadow!8
2019-09-16 13:21:49 +00:00
Laurent Bigonville 4d8a10d86c Move the call to pam_motd before pam_selinux open
pam_selinux calls setexeccon() with the context of the user, that means
that the first execve() after the call to "pam_selinux open" will be
executed in the user's context.

As pam_motd in debian calls system() to run run-parts to generate the
motd dynamically we need to be sure that this is done before that so it
runs in the context of the login executable.
2019-09-03 17:00:06 +02:00
Balint Reczey 9bda99f55d Update changelog debian/1%4.7-2 2019-07-16 18:49:41 +02:00
Balint Reczey 927c6cbdd6 Merge branch 'fix-securetty-news' into 'master'
Improve NEWS entry about securetty

See merge request debian/shadow!7
2019-07-16 15:11:11 +00:00
Gaudenz Steinlin 8f33168316 Improve NEWS entry about securetty
The original version was unclear because it was missing a not in the second part of the sentence.
2019-07-16 07:36:39 +00:00
Balint Reczey 488bb269c9 Update changelog 2019-07-15 23:45:51 +02:00
Balint Reczey 1a76a81ccc Remove Christian Perrier from Uploaders according to his request
Thank you for maintaining shadow for long years!

Closes: #893944, #927576
2019-07-15 23:11:39 +02:00
Balint Reczey 1e63ff4abc Remove obsolete /etc/cron.daily/passwd in maintainer scripts
Closes: #932017
2019-07-15 12:51:34 +02:00
Balint Reczey 8931f490ed Update changelog debian/1%4.7-1 2019-07-08 15:59:16 +02:00
Balint Reczey 1ddb81753d Clean up /etc/securetty properly on upgrade 2019-07-08 15:46:55 +02:00
Balint Reczey 252ca1a609 debian/NEWS: Fix version of latest entry 2019-07-08 15:36:32 +02:00
Balint Reczey 3709c159af Run autopkgtest in Salsa CI when it exists 2019-06-23 22:25:01 +02:00
Balint Reczey 00c091542c Update changelog 2019-06-23 22:13:18 +02:00
Balint Reczey 084a543a03 Refresh patches 2019-06-23 22:11:48 +02:00
Balint Reczey 4793149a12 Update upstream source from tag 'upstream/4.7'
Update to upstream version '4.7'
with Debian dir ae6ca0721c
2019-06-23 22:07:03 +02:00
Balint Reczey b28d45d2bd New upstream version 4.7 upstream/4.7 2019-06-23 22:06:37 +02:00
Balint Reczey d04fc57f13 Fix checking upstream tarball's OpenPGP signature 2019-06-23 16:49:11 +02:00
Balint Reczey 1daf68f0a3 Ship some missing man files 2019-06-23 16:17:34 +02:00
Balint Reczey 58ead426f4 Migrate to dh from cdbs 2019-06-23 16:02:51 +02:00
Balint Reczey 9be33624de Update changelog 2019-06-23 15:48:31 +02:00
Balint Reczey f1f3ef5674 Stop shipping and honoring /etc/securetty
Closes: #731656, #830255, #879903, #920764, #771675, #917893, #607073
2019-06-23 15:48:00 +02:00
Balint Reczey c60535694b Update changelog 2019-06-19 15:59:55 +02:00
Balint Reczey 7bc992f580 Drop Lintian override for su, it is not shipped in login anymore 2019-06-19 14:51:45 +02:00
Balint Reczey 7c34f34109 Merge branch 'master' into 'master'
Remove cron daily backup

See merge request debian/shadow!6
2019-06-19 10:09:37 +00:00
Balint Reczey e153c45690 Update changelog 2019-06-19 00:46:57 +02:00
Bryan Quigley 9c70ce4480 Remove cron daily backup
It was added in 2010 (#554170) as a split off from a previous cron
job.  I haven't seen an arguement for why it's useful to keep.

Depending on when a mistake occurs in one of the files it backups
it will provide variable recovery time of 0 to 24hours.
2019-06-17 09:38:53 -07:00
Balint Reczey 6170e87bd5 Add Salsa CI configuration 2019-05-14 17:07:31 +02:00
Balint Reczey 2ace7fb8f5 Merge remote-tracking branch 'origin/master' 2019-05-14 16:42:35 +02:00