CVE-2020-13776
Summary
| CVE | CVE-2020-13776 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-03 03:15:00 UTC |
| Updated | 2023-11-07 03:16:00 UTC |
| Description | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 32 Update: systemd-245.7-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| User names beginning with 0x being interpreted as user identifiers · Issue #15985 · systemd/systemd · GitHub |
MISC |
github.com |
Third Party Advisory |
| CVE-2020-13776 Systemd Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: systemd-245.7-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159197 Oracle Enterprise Linux Security Update for systemd (ELSA-2021-1611)
- 239327 Red Hat Update for systemd (RHSA-2021:1611)
- 239693 Red Hat Update for systemd (RHSA-2021:3900)
- 354074 Amazon Linux Security Advisory for systemd : ALAS2-2022-1854
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 900080 CBL-Mariner Linux Security Update for systemd 239
- 903506 Common Base Linux Mariner (CBL-Mariner) Security Update for systemd (1793)
- 940184 AlmaLinux Security Update for systemd (ALSA-2021:1611)
- 960704 Rocky Linux Security Update for systemd (RLSA-2021:1611)