This script is Copyright (C) 2007-2014 Tenable Network Security, Inc.
The remote Red Hat host is missing a security update.
An updated shadow-utils package that fixes a security issue and
several bugs is now available.
This update has been rated as having low security impact by the Red
Hat Security Response Team.
The shadow-utils package includes the necessary programs for
converting UNIX password files to the shadow password format, as well
as programs for managing user and group accounts.
A flaw was found in the useradd tool in shadow-utils. A new user's
mailbox, when created, could have random permissions for a short
period. This could allow a local attacker to read or modify the
This update also fixes the following bugs :
* shadow-utils debuginfo package was empty.
* chage.1 and chage -l gave incorrect information about sp_inact.
All users of shadow-utils are advised to upgrade to this updated
package, which contains backported patches to resolve these issues.
See also :
Update the affected shadow-utils package.
Risk factor :
Low / CVSS Base Score : 3.7
Family: Red Hat Local Security Checks
Nessus Plugin ID: 25478 ()
CVE ID: CVE-2006-1174