CVE-2017-1000082
published 2017-07-07CVE-2017-1000082: systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 246-2 (bookworm) | systemd 246-2 (bookworm) |
| debian | systemd | < systemd 234-1 (bookworm) | systemd 234-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-34_on_cbl_mariner_1.0 | — | — |
| systemd_project | systemd | <= 245 | — |
| systemd_project | systemd | >= 0 < 246-2 | 246-2 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
| systemd_project | systemd | >= 0 < 246-2 | 246-2 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
| systemd_project | systemd | >= 0 < 246-2 | 246-2 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
| systemd_project | systemd | >= 0 < 246-2 | 246-2 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
| systemd_project | systemd | >= 229 < 234 | 234 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL