First published: Fri Jul 07 2017(Updated: )
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
systemd | <=233 | |
systemd | >=229<234 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000082 has a medium severity level due to the potential for privilege escalation.
To fix CVE-2017-1000082, upgrade to systemd version 234 or later.
CVE-2017-1000082 affects systemd versions 233 and earlier, as well as versions between 229 and 234.
The risks of CVE-2017-1000082 include unauthorized execution of services with elevated privileges.
CVE-2017-1000082 can affect any environment where vulnerable versions of systemd are deployed, regardless of the specific configuration.