rpm package
suse/shadow&distro=SUSE Linux Enterprise Desktop 12 SP3
pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-7169 | — | < 4.2.1-27.6.1 | 4.2.1-27.6.1 | Feb 15, 2018 | An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certai | ||
| CVE-2017-12424 | Cri | 9.8 | < 4.2.1-27.3.3 | 4.2.1-27.3.3 | Aug 4, 2017 | In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundar | |
| CVE-2016-6252 | Hig | 7.8 | < 4.2.1-27.9.1 | 4.2.1-27.9.1 | Feb 17, 2017 | Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap. |
- CVE-2018-7169Feb 15, 2018affected < 4.2.1-27.6.1fixed 4.2.1-27.6.1
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certai
- affected < 4.2.1-27.3.3fixed 4.2.1-27.3.3
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundar
- affected < 4.2.1-27.9.1fixed 4.2.1-27.9.1
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.