First published: Fri Feb 18 2011(Updated: )
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shadow-utils | =1\-4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0721 is categorized as a medium severity vulnerability due to its potential exploitation by local users.
To fix CVE-2011-0721, update the shadow package to a version that addresses the CRLF injection vulnerabilities.
Local users on systems running shadow version 1:4.1.4 are affected by CVE-2011-0721.
CVE-2011-0721 can facilitate attacks that allow local users to manipulate the /etc/passwd file by exploiting CRLF injection.
No, CVE-2011-0721 is not a remote vulnerability; it requires local access to exploit.