Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHEA-2012:0328 - Product Enhancement Advisory
Issued:
2012-02-22
Updated:
2012-02-22

RHEA-2012:0328 - Product Enhancement Advisory

  • Overview
  • Updated Packages

Synopsis

passwd enhancement update

Type/Severity

Product Enhancement Advisory

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An updated passwd package that adds two enhancements is now available for Red
Hat Enterprise Linux 6.

Description

The passwd packages contain a system utility, "passwd", which changes passwords
and displays password status information using the Pluggable Authentication
Modules (PAM) and Libuser libraries.

This update adds the following enhancements:

  • The passwd command now supports a new option, "-e", that allows the system

administrator to expire the password of the specified user so that the user is
forced to change the password on the next login attempt. (BZ#791139)

  • The passwd executable file is a setuid program so it needs to be well

protected against various types of attacks. With this update, passwd has been
built with the Position Independent Executables (PIE) flag, "-fPIE -pie", and
the full read-only relocations (RELRO) flags, "-Wl,-z,relro,-z,now". The passwd
binary is now well protected against "return-to-text" and memory corruption
attacks and also against attacks based on the program's ELF section overwriting.
(BZ#791143)

All users of passwd are advised to upgrade to this updated package, which adds
these enhancements.

Solution

Before applying this update, make sure all previously-released errata relevant
to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Affected Products

  • Red Hat Enterprise Linux Server 6 x86_64
  • Red Hat Enterprise Linux Server 6 i386
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 6.2 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 6.2 i386
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 i386
  • Red Hat Enterprise Linux Workstation 6 x86_64
  • Red Hat Enterprise Linux Workstation 6 i386
  • Red Hat Enterprise Linux Desktop 6 x86_64
  • Red Hat Enterprise Linux Desktop 6 i386
  • Red Hat Enterprise Linux for IBM z Systems 6 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 6.2 s390x
  • Red Hat Enterprise Linux for Power, big endian 6 ppc64
  • Red Hat Enterprise Linux for Power, big endian - Extended Update Support 6.2 ppc64
  • Red Hat Enterprise Linux for Scientific Computing 6 x86_64
  • Red Hat Enterprise Linux Server from RHUI 6 x86_64
  • Red Hat Enterprise Linux Server from RHUI 6 i386
  • Red Hat Enterprise Linux Server - Extended Update Support from RHUI 6.2 x86_64
  • Red Hat Enterprise Linux Server - Extended Update Support from RHUI 6.2 i386
  • Red Hat Storage 2.0 x86_64
  • Red Hat Gluster Storage Server for On-premise 2.0 x86_64
  • Red Hat Storage for Public Cloud (via RHUI) 2.0 x86_64
  • Red Hat Enterprise Linux Server - AUS 6.2 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6 s390x

Fixes

  • BZ - 791143 - passwd should be compiled with PIE and RELRO flags

CVEs

(none)

References

(none)

Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12

Red Hat Enterprise Linux for x86_64 - Extended Update Support 6.2

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12

Red Hat Enterprise Linux Workstation 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12

Red Hat Enterprise Linux Desktop 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d

Red Hat Enterprise Linux for IBM z Systems 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
s390x
passwd-0.77-4.el6_2.2.s390x.rpm SHA-256: 4799a23aeca6fe40c89b5e064440f8e53b032942a00e81932f412544af12204a
passwd-debuginfo-0.77-4.el6_2.2.s390x.rpm SHA-256: 6d792827729ec98476486e2734ea1bb920129bf358d99808ac7ee21da30793ee

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 6.2

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
s390x
passwd-0.77-4.el6_2.2.s390x.rpm SHA-256: 4799a23aeca6fe40c89b5e064440f8e53b032942a00e81932f412544af12204a
passwd-debuginfo-0.77-4.el6_2.2.s390x.rpm SHA-256: 6d792827729ec98476486e2734ea1bb920129bf358d99808ac7ee21da30793ee

Red Hat Enterprise Linux for Scientific Computing 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d

Red Hat Enterprise Linux Server from RHUI 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12

Red Hat Storage 2.0

SRPM
x86_64

Red Hat Gluster Storage Server for On-premise 2.0

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d

Red Hat Enterprise Linux Server - AUS 6.2

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d

Red Hat Enterprise Linux Server - Extended Life Cycle Support 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12

Red Hat Enterprise Linux for Power, big endian 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
ppc64
passwd-0.77-4.el6_2.2.ppc64.rpm SHA-256: 00468ff84abc7721ad56236a7f5f7814085ecb5fb5f62f582d3bb01c7397be27
passwd-debuginfo-0.77-4.el6_2.2.ppc64.rpm SHA-256: 3f8333eacdd21238e35fb8c6da44c76db32c8d4f4e53863a5fc24fcf4dbf395f

Red Hat Enterprise Linux for Power, big endian - Extended Update Support 6.2

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
ppc64
passwd-0.77-4.el6_2.2.ppc64.rpm SHA-256: 00468ff84abc7721ad56236a7f5f7814085ecb5fb5f62f582d3bb01c7397be27
passwd-debuginfo-0.77-4.el6_2.2.ppc64.rpm SHA-256: 3f8333eacdd21238e35fb8c6da44c76db32c8d4f4e53863a5fc24fcf4dbf395f

Red Hat Enterprise Linux Server - Extended Update Support from RHUI 6.2

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d
i386
passwd-0.77-4.el6_2.2.i686.rpm SHA-256: c40eb82364776c84343599bc8a6f11a1ffae66b56f038e28b7545deba44948d9
passwd-debuginfo-0.77-4.el6_2.2.i686.rpm SHA-256: 4772f23997d6266f10f1bc25d35e89c29d69b56896d47d71824cd9e588eacc12

Red Hat Storage for Public Cloud (via RHUI) 2.0

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
x86_64
passwd-0.77-4.el6_2.2.x86_64.rpm SHA-256: 89e0ac24b9948d9e92261e8412860e6233b86bfb17e1012031bed2b341eafdb7
passwd-debuginfo-0.77-4.el6_2.2.x86_64.rpm SHA-256: 4cba1735e2ec9b4933e46178dd8a6613ac45bdd89e616e4d8f9d6ca725df762d

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6

SRPM
passwd-0.77-4.el6_2.2.src.rpm SHA-256: 0be34fa05661c78fa737d48238d3937eea784e96510808988a1aaf6daa958d5e
s390x
passwd-0.77-4.el6_2.2.s390x.rpm SHA-256: 4799a23aeca6fe40c89b5e064440f8e53b032942a00e81932f412544af12204a
passwd-debuginfo-0.77-4.el6_2.2.s390x.rpm SHA-256: 6d792827729ec98476486e2734ea1bb920129bf358d99808ac7ee21da30793ee

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2022 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter