SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4641

This may allow an attacker with enough access to retrieve the password from the memory.

MEDIUM 5.5EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.25% probability · 17th percentile
CISA KEV
Not listed
Weakness
CWE-303, CWE-287
Affected
shadow-maint/shadow-utils · redhat/codeready linux builder · redhat/codeready linux builder for arm64 · redhat/codeready linux builder for ibm z systems · redhat/codeready linux builder for power little endian · redhat/enterprise linux · redhat/enterprise linux for arm 64 · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for power little endian
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.