Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade shadow | Jul 30, 2024 | Feb 19, 2011 |
| Gentoo Linux | — | Upgrade net-misc/mrouted.Upgrade net-misc/vino.Upgrade sys-apps/shadow.Upgrade x11-apps/xrdb.Upgrade dev-libs/xmlsec.Upgrade net-libs/libsoup.Upgrade app-admin/syslog-ng.Upgrade games-sports/racer-bin.Upgrade media-libs/xine-lib.Upgrade media-libs/fmod.Upgrade dev-php/PEAR-PEAR.Upgrade dev-db/unixODBC.Upgrade dev-php/PEAR-Mail.Upgrade net-misc/rsync.Upgrade dev-util/oprofile.Upgrade net-analyzer/sflowtool.Upgrade media-sound/lastfmplayer.Upgrade gnome-base/gdm.Upgrade sys-fs/lvm2.Upgrade dev-vcs/gitolite.Upgrade dev-util/qt-creator.Upgrade net-libs/webkit-gtk.Upgrade app-office/gnucash.Upgrade app-misc/ca-certificates.Upgrade sys-cluster/resource-agents. | Oct 30, 2017 | Feb 18, 2011 |
| Ubuntu | — | Upgrade passwd | Nov 8, 2024 | Feb 19, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub