cbcvebase.
CVE-2023-4641
published 2023-12-27

CVE-2023-4641: A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt…

PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.26%
17.2th percentile
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianshadow< shadow 1:4.13+dfsg1-1+deb12u1 (bookworm)shadow 1:4.13+dfsg1-1+deb12u1 (bookworm)
msrccbl2_shadow-utils_4.9-14_on_cbl_mariner_2.0
redhatcodeready_linux_builder
redhatcodeready_linux_builder
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_power_little_endian
redhatcodeready_linux_builder_for_power_little_endian
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian
shadow-maintshadow-utils< 4.14.04.14.0
shadow_projectshadow>= 0 < 1:4.8.1-1+deb11u11:4.8.1-1+deb11u1
shadow_projectshadow>= 0 < 1:4.13+dfsg1-1+deb12u11:4.13+dfsg1-1+deb12u1
shadow_projectshadow>= 0 < 1:4.13+dfsg1-21:4.13+dfsg1-2
shadow_projectshadow>= 0 < 1:4.13+dfsg1-21:4.13+dfsg1-2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.