PT-2021-22794 · Unknown+1 · Opensysusers+1

Ansgar

·

Published

2021-08-25

·

Updated

2022-07-12

·

CVE-2021-40084

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions opensysusers versions 0.6 and earlier
Description The issue arises from the unsafe use of eval on files in sysusers.d that may contain shell metacharacters. This allows for command execution via a crafted GECOS field, which is not the case with systemd-sysusers, a program that follows the same specification.
Recommendations For opensysusers versions 0.6 and earlier, consider disabling the use of eval on files in sysusers.d until a patch is available. Restrict access to the sysusers.d directory to minimize the risk of exploitation. Avoid using crafted GECOS fields in the affected files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40084

Affected Products

Debian
Opensysusers