PT-2021-22794 · Unknown+1 · Opensysusers+1
Ansgar
·
Published
2021-08-25
·
Updated
2022-07-12
·
CVE-2021-40084
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
opensysusers versions 0.6 and earlier
Description
The issue arises from the unsafe use of eval on files in sysusers.d that may contain shell metacharacters. This allows for command execution via a crafted GECOS field, which is not the case with systemd-sysusers, a program that follows the same specification.
Recommendations
For opensysusers versions 0.6 and earlier, consider disabling the use of eval on files in sysusers.d until a patch is available. Restrict access to the sysusers.d directory to minimize the risk of exploitation. Avoid using crafted GECOS fields in the affected files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Opensysusers