CVE-2017-12424
Summary
| CVE | CVE-2017-12424 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-04 09:29:00 UTC |
| Updated | 2021-03-23 20:02:00 UTC |
| Description | In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Shadow: Buffer overflow (GLSA 201710-16) — Gentoo Security |
GENTOO |
security.gentoo.org |
|
| Bug #1266675 “newusers error adding more than one user” : Bugs : shadow package : Ubuntu |
CONFIRM |
bugs.launchpad.net |
Issue Tracking, Third Party Advisory |
| #756630 - shadow: CVE-2017-12424: newusers fails with multiple users - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 2596-1] shadow security update |
MLIST |
lists.debian.org |
|
| Fix buffer overflow if NULL line is present in db. · shadow-maint/shadow@954e3d2 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178494 Debian Security Update for shadow (DLA 2596-1)
- 198646 Ubuntu Security Notification for shadow Vulnerabilities (USN-5254-1)
- 501251 Alpine Linux Security Update for shadow
- 505410 Alpine Linux Security Update for shadow
- 710504 Gentoo Linux Shadow Buffer overflow Vulnerability (GLSA 201710-16)