In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade shadow | May 7, 2019 | Aug 4, 2017 |
| Debian | — | Upgrade shadow | Mar 19, 2021 | Aug 4, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/shadow. | Oct 30, 2017 | Aug 4, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade shadow-utils | Dec 4, 2019 | Aug 4, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade shadow-utils | Jun 28, 2018 | Aug 4, 2017 |
| Suse | — | Upgrade shadow | Nov 8, 2017 | Aug 4, 2017 |
| Ubuntu | — | Upgrade uidmap (Ubuntu Pro)Upgrade loginUpgrade uidmapUpgrade passwdUpgrade passwd (Ubuntu Pro)Upgrade login (Ubuntu Pro) | Jan 28, 2022 | Aug 4, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 4, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub