[Pkg-shadow-devel] Bug#638263: shadowconfig uses "pwck -p" and "grpck -p" which aren't actually supported

Thomas Bushnell, BSG tb at becket.net
Thu Aug 18 02:37:47 UTC 2011


Package: passwd
Version: 1:4.1.4.2+svn3283-2+squeeze1
Severity: important

/sbin/shadowconfig from the passwd package uses "pwck -p" and "grpck -p". On
some other systems, the -p flag to these programs says to silently fix
problems found in those files.

But the Debian versions do not actually do that. The Debian versions ignore
the -p option, and then go ahead and prompt for confirmation before making
changes.

This can be dangerous at install time. If the install image has problems in
the group or passwd files (for example, mention of an unknown user in the
group file), then when the install calles "shadowconfig on", it will try to
read from stdin and the install will hang.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/pkg-shadow-devel/attachments/20110817/8e25b59c/attachment.html>


More information about the Pkg-shadow-devel mailing list