PT-2011-2584 · Gnu · Shadow

Kees Cook

·

Published

2011-02-18

·

Updated

2017-08-17

·

CVE-2011-0721

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions shadow version 1:4.1.4
Description The issue concerns CRLF injection vulnerabilities in the chfn and chsh utilities within the shadow package. This allows local users to modify the /etc/passwd file by adding new users or groups via the GECOS field.
Recommendations For shadow version 1:4.1.4, consider restricting access to the chfn and chsh utilities until a patch is available. As a temporary workaround, avoid using the GECOS field in the chfn and chsh utilities to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0721
DSA-2164-1

Affected Products

Shadow