CVE-2021-40084
Summary
| CVE | CVE-2021-40084 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-25 01:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| #992058 - opensysusers: uses `eval` on data that is not supposed to be safe to eval - Debian Bug report logs |
MISC |
bugs.debian.org |
|
| Releases · artix-linux/opensysusers · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184498 Debian Security Update for opensysusers (CVE-2021-40084)