PT-2017-8943 · Mageia · Shadow-Utils

Publicado

2017-01-27

·

Atualizado

2017-01-27

·

CVE-2016-6251

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
It was found that shadow-utils-4.2.1 had a potentially unsafe use of getlogin with the concern that the utmp entry might have a spoofed username associated with a correct uid (CVE-2016-6251).
It was found that shadow-utils-4.2.1 had an incorrect integer handling problem where it looks like the int wrap is exploitable as a LPE, as the kernel is using 32bit uid's that are truncated from unsigned longs (64bit on x64) as returned by simple strtoul() [map write()]. (CVE-2016-6252).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2016-6251
MGASA-2017-0024

Produtos afetados

Shadow-Utils