This script is Copyright (C) 2013 Tenable Network Security, Inc.
The remote Oracle Linux host is missing a security update.
From Red Hat Security Advisory 2007:0431 :
An updated shadow-utils package that fixes a security issue and
several bugs is now available.
This update has been rated as having low security impact by the Red
Hat Security Response Team.
The shadow-utils package includes the necessary programs for
converting UNIX password files to the shadow password format, as well
as programs for managing user and group accounts.
A flaw was found in the useradd tool in shadow-utils. A new user's
mailbox, when created, could have random permissions for a short
period. This could allow a local attacker to read or modify the
This update also fixes the following bugs :
* shadow-utils debuginfo package was empty.
* chage.1 and chage -l gave incorrect information about sp_inact.
All users of shadow-utils are advised to upgrade to this updated
package, which contains backported patches to resolve these issues.
See also :
Update the affected shadow-utils package.
Risk factor :
Low / CVSS Base Score : 3.7
Family: Oracle Linux Local Security Checks
Nessus Plugin ID: 67515 ()
CVE ID: CVE-2006-1174