CVE-2016-6252
published 2017-02-17CVE-2016-6252: Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.4th percentile
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | < shadow 1:4.4-1 (bookworm) | shadow 1:4.4-1 (bookworm) |
| shadow_project | shadow | — | — |
| shadow_project | shadow | >= 0 < 1:4.4-1 | 1:4.4-1 |
| shadow_project | shadow | >= 0 < 1:4.4-1 | 1:4.4-1 |
| shadow_project | shadow | >= 0 < 1:4.4-1 | 1:4.4-1 |
| shadow_project | shadow | >= 0 < 1:4.4-1 | 1:4.4-1 |
| shadow_project | shadow | >= 0 < 1:4.1.5.1-1ubuntu9.5 | 1:4.1.5.1-1ubuntu9.5 |
| shadow_project | shadow | >= 0 < 1:4.1.5.1-1ubuntu9.4 | 1:4.1.5.1-1ubuntu9.4 |
| shadow_project | shadow | >= 0 < 1:4.2-3.1ubuntu5.3 | 1:4.2-3.1ubuntu5.3 |
| shadow_project | shadow | >= 0 < 1:4.2-3.1ubuntu5.2 | 1:4.2-3.1ubuntu5.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8rg4-9fq3-cf7g: Integer overflow in shadow 4
ghsa_unreviewed·2022-05-17
CVE-2016-6252 [HIGH] CWE-190 GHSA-8rg4-9fq3-cf7g: Integer overflow in shadow 4
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
OSV
shadow regression
osv·2017-05-17·CVSS 7.8
CVE-2016-6252 [HIGH] shadow regression
shadow regression
USN-3276-1 intended to fix a vulnerability in su. The solution introduced
a regression in su signal handling. This update modifies the security fix.
We apologize for the inconvenience.
Original advisory details:
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local
attacker could cause su to send SIGKILL to other processes with
root privileges. (CVE-2017-2616)
OSV
shadow vulnerabilities
osv·2017-05-05·CVSS 7.8
CVE-2016-6252 [HIGH] shadow vulnerabilities
shadow vulnerabilities
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local
attacker could cause su to send SIGKILL to other processes with
root privileges. (CVE-2017-2616)
OSV
CVE-2016-6252: Integer overflow in shadow 4
osv·2017-02-17·CVSS 7.8
CVE-2016-6252 [HIGH] CVE-2016-6252: Integer overflow in shadow 4
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
Ubuntu
shadow vulnerability
vendor_ubuntu·2017-11-14·CVSS 7.8
CVE-2017-2616 [HIGH] shadow vulnerability
Title: shadow vulnerability
Summary: su could be made to crash or stop programs as an administrator.
USN-3276-1 and USN-3276-2 fixed vulnerabilities in shadow. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
shadow regression
vendor_ubuntu·2017-05-17·CVSS 7.8
CVE-2016-6252 [HIGH] shadow regression
Title: shadow regression
Summary: USN-3276-1 introduced a regression in su.
USN-3276-1 intended to fix a vulnerability in su. The solution introduced
a regression in su signal handling. This update modifies the security fix.
We apologize for the inconvenience.
Original advisory details:
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local
attacker could cause su to send SIGKILL to other processes with
root privileges. (CVE-2017-2616)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
shadow vulnerabilities
vendor_ubuntu·2017-05-05·CVSS 7.8
CVE-2016-6252 [HIGH] shadow vulnerabilities
Title: shadow vulnerabilities
Summary: su could be made to crash or stop programs as an administrator.
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local
attacker could cause su to send SIGKILL to other processes with
root privileges. (CVE-2017-2616)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
shadow-utils: Incorrect integer handling results in LPE
vendor_redhat·2016-07-19·CVSS 7.8
CVE-2016-6252 [HIGH] CWE-190 shadow-utils: Incorrect integer handling results in LPE
shadow-utils: Incorrect integer handling results in LPE
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
Package: shadow-utils (Red Hat Enterprise Linux 5) - Not affected
Package: shadow-utils (Red Hat Enterprise Linux 6) - Not affected
Package: shadow-utils (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-6252: shadow - Integer overflow in shadow 4.2.1 allows local users to gain privileges via craft...
vendor_debian·2016·CVSS 7.8
CVE-2016-6252 [HIGH] CVE-2016-6252: shadow - Integer overflow in shadow 4.2.1 allows local users to gain privileges via craft...
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
Scope: local
bookworm: resolved (fixed in 1:4.4-1)
bullseye: resolved (fixed in 1:4.4-1)
forky: resolved (fixed in 1:4.4-1)
sid: resolved (fixed in 1:4.4-1)
trixie: resolved (fixed in 1:4.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6251 CVE-2016-6252 shadow-utils: various flaws [fedora-all]
bugzilla·2016-07-21·CVSS 7.8
CVE-2016-6251 [HIGH] CVE-2016-6251 CVE-2016-6252 shadow-utils: various flaws [fedora-all]
CVE-2016-6251 CVE-2016-6252 shadow-utils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2016-6252 shadow-utils: Incorrect integer handling results in LPE
bugzilla·2016-07-21·CVSS 7.8
CVE-2016-6252 [HIGH] CVE-2016-6252 shadow-utils: Incorrect integer handling results in LPE
CVE-2016-6252 shadow-utils: Incorrect integer handling results in LPE
An integer overflow vulnerability was found in shadow-utils. Attacker can use this for local privileges escalation.
References:
http://seclists.org/oss-sec/2016/q3/111
CVE assignment:
http://seclists.org/oss-sec/2016/q3/115
Discussion:
Created shadow-utils tracking bugs for this issue:
Affects: fedora-all [bug 1358629]
---
Upstream bug:
https://github.com/shadow-maint/shadow/issues/27
---
The rhel-5 package shadow-4.0.17 does not include this vulnerability.
rhel-6 and rhel-7 shadow-4.1.15-1 include the getulong() function to which a portion of the upstream patch applies, but it is used much less widely and the idmapping does not exist in this version. Thus the demonstration from oss-sec using `newuidmap` is
http://www.debian.org/security/2017/dsa-3793http://www.openwall.com/lists/oss-security/2016/07/19/6http://www.openwall.com/lists/oss-security/2016/07/19/7http://www.openwall.com/lists/oss-security/2016/07/20/2http://www.openwall.com/lists/oss-security/2016/07/25/7http://www.securityfocus.com/bid/92055https://bugzilla.suse.com/show_bug.cgi?id=979282https://github.com/shadow-maint/shadow/issues/27https://security.gentoo.org/glsa/201706-02http://www.debian.org/security/2017/dsa-3793http://www.openwall.com/lists/oss-security/2016/07/19/6http://www.openwall.com/lists/oss-security/2016/07/19/7http://www.openwall.com/lists/oss-security/2016/07/20/2http://www.openwall.com/lists/oss-security/2016/07/25/7http://www.securityfocus.com/bid/92055https://bugzilla.suse.com/show_bug.cgi?id=979282https://github.com/shadow-maint/shadow/issues/27https://security.gentoo.org/glsa/201706-02
2017-02-17
Published