First published: Fri Feb 18 2011(Updated: )
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian shadow | =1\-4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.