Description
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2596-1 | shadow security update |
EUVD |
EUVD-2017-3997 | In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts. |
Ubuntu USN |
USN-5254-1 | shadow vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T18:36:56.443Z
Reserved: 2017-08-04T00:00:00.000Z
Link: CVE-2017-12424
No data.
Status : Modified
Published: 2017-08-04T09:29:00.187
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-12424
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN