CVE-2023-29383
Summary
| CVE | CVE-2023-29383 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-14 22:15:00 UTC |
| Updated | 2023-04-24 18:05:00 UTC |
| Description | In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Control character check by tomspiderlabs · Pull Request #687 · shadow-maint/shadow · GitHub |
MISC |
github.com |
|
| CVE-2023-29383: Abusing Linux chfn to Misrepresent etc passwd | Trustwave |
MISC |
www.trustwave.com |
|
| www.trustwave.com/en-us/resources/security-resources/security-advisories |
MISC |
www.trustwave.com |
|
| Added control character check · shadow-maint/shadow@e5905c4 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 503267 Alpine Linux Security Update for shadow
- 506239 Alpine Linux Security Update for shadow
- 673177 EulerOS Security Update for shadow (EulerOS-SA-2023-2343)
- 673183 EulerOS Security Update for shadow (EulerOS-SA-2023-2323)
- 673219 EulerOS Security Update for shadow (EulerOS-SA-2023-2368)
- 673230 EulerOS Security Update for shadow (EulerOS-SA-2023-2394)
- 673982 EulerOS Security Update for shadow (EulerOS-SA-2023-2668)
- 674054 EulerOS Security Update for shadow (EulerOS-SA-2023-2710)
- 753953 SUSE Enterprise Linux Security Update for shadow (SUSE-SU-2023:2070-1)
- 753954 SUSE Enterprise Linux Security Update for shadow (SUSE-SU-2023:2069-1)
- 753955 SUSE Enterprise Linux Security Update for shadow (SUSE-SU-2023:2068-1)
- 753956 SUSE Enterprise Linux Security Update for shadow (SUSE-SU-2023:2067-1)