Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12424

Опубликовано: 31 мар. 2017
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

A buffer overflow flaw leading to heap memory corruption was found in the shadow-utils's newusers utility. A local, authenticated attacker could potentially use this flaw to crash the newusers process by supplying crafted data to it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5shadow-utilsNot affected
Red Hat Enterprise Linux 6shadow-utilsNot affected
Red Hat Enterprise Linux 7shadow-utilsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1478359shadow-utils: Buffer overflow via newusers tool

EPSS

Процентиль: 84%
0.02659
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

CVSS3: 9.8
nvd
около 9 лет назад

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

CVSS3: 9.8
debian
около 9 лет назад

In shadow before 4.5, the newusers tool could be made to manipulate in ...

suse-cvrf
почти 9 лет назад

Security update for shadow

suse-cvrf
почти 9 лет назад

Security update for shadow

EPSS

Процентиль: 84%
0.02659
Низкий

4.5 Medium

CVSS3