Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000082

Опубликовано: 07 июл. 2017
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

Отчет

For more information on the impact of numeric usernames in Red Hat Enterprise Linux, please see https://access.redhat.com/solutions/3103631

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7systemdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1468427systemd: fails to parse usernames that start with digits

EPSS

Процентиль: 89%
0.03878
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

CVSS3: 9.8
nvd
около 9 лет назад

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

CVSS3: 9.8
debian
около 9 лет назад

systemd v233 and earlier fails to safely parse usernames starting with ...

CVSS3: 9.8
github
больше 4 лет назад

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

CVSS3: 9.8
fstec
около 9 лет назад

Уязвимость службы анализирования имен пользователей демона Systemd, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю запустить службу с root-привилегиями

EPSS

Процентиль: 89%
0.03878
Низкий

7.2 High

CVSS3