Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12424

Опубликовано: 04 авг. 2017
Источник: debian
EPSS Низкий

Описание

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shadowfixed1:4.5-1package
shadowno-dsajessiepackage
shadowno-dsawheezypackage

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1266675

  • https://github.com/shadow-maint/shadow/commit/954e3d2e7113e9ac06632aee3c69b8d818cc8952 (4.5)

EPSS

Процентиль: 84%
0.02659
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

CVSS3: 4.5
redhat
больше 9 лет назад

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

CVSS3: 9.8
nvd
около 9 лет назад

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

suse-cvrf
почти 9 лет назад

Security update for shadow

suse-cvrf
почти 9 лет назад

Security update for shadow

EPSS

Процентиль: 84%
0.02659
Низкий