yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute
Description
An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping.
Impact: an administrator who manages users against an external/federated LDAP directory via yast2 users triggers root command execution the moment they view or edit that particular user's "Password Settings" tab. No "join domain" or trust setup is required, just browsing/editing one user entry.
This issue affects yast2-users through 5.0.8.
Affected products
2- Range: <=5.0.8
- Range: <=5.0.8
Patches
Vulnerability mechanics
References
1- bugzilla.suse.com/show_bug.cgimitreissue-tracking
News mentions
0No linked articles in our index yet.