CVE-2017-1000082: Critical severity systemd vulnerability
Published Jul 7, 2017
·Updated
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
Affected Software
2 affected components
Systemd Project Systemd<=233
Systemd Project Systemd>=229<234
Remediation
Patch Available
Patch Available
Event History
Jul 7, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000082?
CVE-2017-1000082 has a medium severity level due to the potential for privilege escalation.
2
How do I fix CVE-2017-1000082?
To fix CVE-2017-1000082, upgrade to systemd version 234 or later.
3
What versions of systemd are affected by CVE-2017-1000082?
CVE-2017-1000082 affects systemd versions 233 and earlier, as well as versions between 229 and 234.
4
What are the potential risks of CVE-2017-1000082?
The risks of CVE-2017-1000082 include unauthorized execution of services with elevated privileges.
5
Is CVE-2017-1000082 an environment-specific vulnerability?
CVE-2017-1000082 can affect any environment where vulnerable versions of systemd are deployed, regardless of the specific configuration.