Severity
9.8CRITICAL
EPSS
0.3%
top 50.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 7
Latest updateMay 13

Description

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDsystemd_project/systemd229234
Debiansystemd< 234-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pp67-7cmm-9pp7: systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e2022-05-13
CVEList
CVE-2017-1000082: systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e2017-07-07
OSV
CVE-2017-1000082: systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e2017-07-07

📋Vendor Advisories

4
Microsoft
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits as demonstrated by use of root privileges when privileges of the 0x0 user accou2020-06-09
Red Hat
systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits2020-05-31
Red Hat
systemd: fails to parse usernames that start with digits2017-07-07
Debian
CVE-2017-1000082: systemd - systemd v233 and earlier fails to safely parse usernames starting with a numeric...2017

💬Community

3
Bugzilla
CVE-2020-13776 systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits2020-06-09
Bugzilla
CVE-2017-1000082 systemd: fails to parse usernames that start with digits [fedora-all]2017-07-07
Bugzilla
CVE-2017-1000082 systemd: fails to parse usernames that start with digits2017-07-07
CVE-2017-1000082 (CRITICAL CVSS 9.8) | systemd v233 and earlier fails to s | cvebase.io