PT-2017-8943 · Mageia · Shadow-Utils
Published
2017-01-27
·
Updated
2017-01-27
·
CVE-2016-6251
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was found that shadow-utils-4.2.1 had a potentially unsafe use of
getlogin with the concern that the utmp entry might have a spoofed
username associated with a correct uid (CVE-2016-6251).
It was found that shadow-utils-4.2.1 had an incorrect integer handling
problem where it looks like the int wrap is exploitable as a LPE, as the
kernel is using 32bit uid's that are truncated from unsigned longs
(64bit on x64) as returned by simple strtoul() [map write()].
(CVE-2016-6252).
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shadow-Utils