PT-2017-8943 · Mageia · Shadow-Utils
Publicado
2017-01-27
·
Atualizado
2017-01-27
·
CVE-2016-6251
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
It was found that shadow-utils-4.2.1 had a potentially unsafe use of
getlogin with the concern that the utmp entry might have a spoofed
username associated with a correct uid (CVE-2016-6251).
It was found that shadow-utils-4.2.1 had an incorrect integer handling
problem where it looks like the int wrap is exploitable as a LPE, as the
kernel is using 32bit uid's that are truncated from unsigned longs
(64bit on x64) as returned by simple strtoul() [map write()].
(CVE-2016-6252).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Shadow-Utils