VYPR

rpm package

suse/shadow&distro=SUSE Linux Enterprise Server for Raspberry Pi 12 SP2

pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2

Vulnerabilities (2)

  • CVE-2018-7169Feb 15, 2018
    affected < 4.2.1-27.6.1fixed 4.2.1-27.6.1

    An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certai

  • CVE-2017-12424CriAug 4, 2017
    affected < 4.2.1-27.3.3fixed 4.2.1-27.3.3

    In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundar