DESCRIPTION
shadow-utils[1] is a collection of utilities for managing shadow
password files and user/group accounts.
Martin Schulze reported a vulnerability[2] in the passwd_check()
function in "libmisc/pwdcheck.c" which is used by chfn and chsh and
thus may allow a local attacker to use them to change the standard
shell of other users or modify their GECOS information (full name,
phone number...).
SOLUTION
It is recommended that all Conectiva Linux users upgrade their
packages.