CVE-2020-13776

Severity
6.7MEDIUM
EPSS
0.1%
top 66.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 24

Description

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

Debiansystemd< 246-2+3

Also affects: Fedora 32

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g2fm-j5p3-x5h7: systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of ro2022-05-24
OSV
CVE-2020-13776: systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of ro2020-06-03
CVEList
CVE-2020-13776: systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of ro2020-06-03

📋Vendor Advisories

3
Microsoft
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits as demonstrated by use of root privileges when privileges of the 0x0 user accou2020-06-09
Red Hat
systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits2020-05-31
Debian
CVE-2020-13776: systemd - systemd through v245 mishandles numerical usernames such as ones composed of dec...2020

💬Community

2
Bugzilla
CVE-2020-13776 systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits2020-06-09
Bugzilla
CVE-2020-13776 systemd: mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits [fedora-all]2020-06-09