In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-shadow | Aug 22, 2024 | Apr 14, 2023 | |
| Debian | debian-upgrade-shadow | Apr 21, 2025 | Apr 14, 2023 | |
| Dell Powerstore Dsa2023366 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Oct 5, 2023 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-shadow | Jul 18, 2023 | Apr 14, 2023 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-shadow | Jan 10, 2024 | Apr 14, 2023 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-shadow | Jul 10, 2023 | Apr 14, 2023 | |
| Suse | — | suse-upgrade-login_defssuse-upgrade-shadow | May 1, 2023 | Apr 14, 2023 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Apr 14, 2023 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Apr 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub