Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 9 DLA-2596-1 Critical: Shadow Suite Privilege Escalation Risk

debian lts
Calendar Grey March 17, 2021
Dist Debian Esm H88
Ubuntu LTS Notice ULA-1920-3 tackles vulnerabilities in LibXYZ to mitigate data exposure threats.
Several vulnerabilities were discovered in the shadow suite of login tools

Summary

CVE-2017-20002

Shadow incorrectly lists pts/0 and pts/1 as physical terminals in
/etc/securetty. This allows local users to login as password-less
users even if they are connected by non-physical means such as SSH
(hence bypassing PAM's nullok_secure configuration). This notably
affects environments such as virtual machines automatically
generated with a default blank root password, allowing all local
users to escalate privileges. It should be noted however that
/etc/securetty will be dropped in Debian 11/bullseye.

CVE-2017-12424

The newusers tool could be made to manipulate internal data
structures in ways unintended by the authors. Malformed input may
lead to crashes (with a buffer overflow or other memory
corruption) or other unspecified behaviors. This crosses a
privilege boundary in, for example, certain web-hosting
environments in which a Control Panel allows an unprivileged user
account to create subaccounts.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: shadow
Version: 1:4.4-4.1+deb9u1
CVE ID: CVE-2017-12424 CVE-2017-20002
Debian Bug: 756630 914957

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here