SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-12424

Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors.

CRITICAL 9.8EPSS 2.66%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.66% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
shadow project/shadow · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.