CVE-2017-12424

CRITICAL

Shadow <4.5 - Memory Corruption

Title source: llm

Description

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

Scores

CVSS v3 9.8
EPSS 0.0064
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-119
Status draft

Affected Products (2)

shadow_project/shadow < 4.5
debian/debian_linux

Timeline

Published Aug 04, 2017
Tracked Since Feb 18, 2026