CVE-2016-6252Integer Overflow or Wraparound in Project Shadow

Severity
7.8HIGHNVD
EPSS
0.1%
top 71.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateMay 17

Description

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianshadow_project/shadow< 1:4.4-1+3
Ubuntushadow_project/shadow< 1:4.1.5.1-1ubuntu9.5+3

Patches

🔴Vulnerability Details

5
GHSA
GHSA-8rg4-9fq3-cf7g: Integer overflow in shadow 42022-05-17
OSV
shadow regression2017-05-17
OSV
shadow vulnerabilities2017-05-05
OSV
CVE-2016-6252: Integer overflow in shadow 42017-02-17
CVEList
CVE-2016-6252: Integer overflow in shadow 42017-02-17

📋Vendor Advisories

4
Ubuntu
shadow regression2017-05-17
Ubuntu
shadow vulnerabilities2017-05-05
Red Hat
shadow-utils: Incorrect integer handling results in LPE2016-07-19
Debian
CVE-2016-6252: shadow - Integer overflow in shadow 4.2.1 allows local users to gain privileges via craft...2016

💬Community

2
Bugzilla
CVE-2016-6251 CVE-2016-6252 shadow-utils: various flaws [fedora-all]2016-07-21
Bugzilla
CVE-2016-6252 shadow-utils: Incorrect integer handling results in LPE2016-07-21
CVE-2016-6252 — Integer Overflow or Wraparound | cvebase