Shadow: Multiple vulnerabilities Multiple vulnerabilities have been found in Shadow, the worst of which might allow privilege escalation. shadow 2017-06-06 2017-06-06 610804 620510 local 4.4-r2 4.4-r2

Shadow is a set of tools to deal with user accounts.

Multiple vulnerabilities have been discovered in Shadow. Please review the CVE identifiers referenced below for details.

A local attacker could possibly cause a Denial of Service condition, gain privileges via crafted input, or SIGKILL arbitrary processes.

There is no known workaround at this time.

All Shadow users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.4-r2"
CVE-2016-6252 CVE-2017-2616 BlueKnight whissi