CVE-2011-0721: Input Validation
Published Feb 18, 2011
·Updated
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.
Affected Software
1 affected component
Debian shadow=1\-4.1.4
Event History
Feb 18, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0721?
CVE-2011-0721 is categorized as a medium severity vulnerability due to its potential exploitation by local users.
2
How do I fix CVE-2011-0721?
To fix CVE-2011-0721, update the shadow package to a version that addresses the CRLF injection vulnerabilities.
3
Who is affected by CVE-2011-0721?
Local users on systems running shadow version 1:4.1.4 are affected by CVE-2011-0721.
4
What types of attacks can CVE-2011-0721 facilitate?
CVE-2011-0721 can facilitate attacks that allow local users to manipulate the /etc/passwd file by exploiting CRLF injection.
5
Is CVE-2011-0721 a remote vulnerability?
No, CVE-2011-0721 is not a remote vulnerability; it requires local access to exploit.