CVE-2013-4235
published 2019-12-03CVE-2013-4235: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNIHAN
EPSS
0.31%
22.9th percentile
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | shadow | < shadow 1:4.12.3+dfsg1-1 (bookworm) | shadow 1:4.12.3+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| shadow | shadow | — | — |
| shadow_project | shadow | >= 0 < 1:4.12.3+dfsg1-1 | 1:4.12.3+dfsg1-1 |
| shadow_project | shadow | >= 0 < 1:4.12.3+dfsg1-1 | 1:4.12.3+dfsg1-1 |
| shadow_project | shadow | >= 0 < 1:4.12.3+dfsg1-1 | 1:4.12.3+dfsg1-1 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
shadow vulnerability
vendor_ubuntu·2022-11-28
CVE-2013-4235 shadow vulnerability
Title: shadow vulnerability
Summary: shadow could be made to overwrite files.
Florian Weimer discovered that shadow was not properly copying and removing
user directory trees, which could lead to a race condition. A local attacker
could possibly use this issue to setup a symlink attack and alter or remove
directories without authorization.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
shadow-utils: TOCTOU race conditions by copying and removing directory trees
vendor_redhat·2015-02-06·CVSS 4.7
CVE-2013-4235 [MEDIUM] CWE-367 shadow-utils: TOCTOU race conditions by copying and removing directory trees
shadow-utils: TOCTOU race conditions by copying and removing directory trees
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
A TOCTOU race condition was discovered in shadow-utils. A local attacker with write privileges in a directory removed or copied by usermod/userdel could potentially exploit this flaw, when the administrator invokes usermod/userdel, to delete or modify other files on the system.
Package: shadow-utils (Red Hat Enterprise Linux 5) - Will not fix
Package: shadow-utils (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2013-4235: shadow - shadow: TOCTOU (time-of-check time-of-use) race condition when copying and remov...
vendor_debian·2013·CVSS 4.7
CVE-2013-4235 [MEDIUM] CVE-2013-4235: shadow - shadow: TOCTOU (time-of-check time-of-use) race condition when copying and remov...
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Scope: local
bookworm: resolved (fixed in 1:4.12.3+dfsg1-1)
bullseye: open
forky: resolved (fixed in 1:4.12.3+dfsg1-1)
sid: resolved (fixed in 1:4.12.3+dfsg1-1)
trixie: resolved (fixed in 1:4.12.3+dfsg1-1)
GHSA
GHSA-2q3w-h8mm-q9v3: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
ghsa_unreviewed·2022-05-05
CVE-2013-4235 [LOW] CWE-367 GHSA-2q3w-h8mm-q9v3: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
OSV
CVE-2013-4235: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
osv·2019-12-03·CVSS 4.7
CVE-2013-4235 [MEDIUM] CVE-2013-4235: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/cve-2013-4235https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4235https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://security-tracker.debian.org/tracker/CVE-2013-4235https://security.gentoo.org/glsa/202210-26https://access.redhat.com/security/cve/cve-2013-4235https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4235https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://security-tracker.debian.org/tracker/CVE-2013-4235https://security.gentoo.org/glsa/202210-26
2019-12-03
Published