cbcvebase.
CVE-2017-12424
published 2017-08-04

CVE-2017-12424: In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to…

PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.66%
84.0th percentile
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianshadow< shadow 1:4.5-1 (bookworm)shadow 1:4.5-1 (bookworm)
paloaltopan-os
shadow_projectshadow< 4.54.5
shadow_projectshadow>= 0 < 1:4.5-11:4.5-1
shadow_projectshadow>= 0 < 1:4.5-11:4.5-1
shadow_projectshadow>= 0 < 1:4.5-11:4.5-1
shadow_projectshadow>= 0 < 1:4.5-11:4.5-1
shadow_projectshadow>= 0 < 1:4.5-1ubuntu2.21:4.5-1ubuntu2.2
shadow_projectshadow>= 0 < 1:4.1.5.1-1ubuntu9.5+esm11:4.1.5.1-1ubuntu9.5+esm1
shadow_projectshadow>= 0 < 1:4.2-3.1ubuntu5.5+esm11:4.2-3.1ubuntu5.5+esm1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.