Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hgh-26fm-566h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

EPSS

Процентиль: 79%
0.01275
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

CVSS3: 9.8
nvd
больше 4 лет назад

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

CVSS3: 9.8
debian
больше 4 лет назад

opensysusers through 0.6 does not safely use eval on files in sysusers ...

EPSS

Процентиль: 79%
0.01275
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77