CVE-2017-12424
CRITICALShadow <4.5 - Memory Corruption
Title source: llmDescription
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.
Scores
CVSS v3
9.8
EPSS
0.0064
EPSS Percentile
70.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-119
Status
draft
Affected Products (2)
shadow_project/shadow
< 4.5
debian/debian_linux
Timeline
Published
Aug 04, 2017
Tracked Since
Feb 18, 2026