Skip to main content

Vendor/product archive

debian / shadow CVEs

Beta · best-effort

8 CVEs tagged to debian / shadow0 Critical, 3 High, 3 Medium, 2 Low, 0 Unrated.

CVE-2017-20002

Published Mar 17, 2021

The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less us…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0721

Published Feb 19, 2011

Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5394

Published Dec 9, 2008

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack o…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1174

Published May 28, 2006

useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which c…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1844

Published Apr 19, 2006

The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and p…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1001

Published Mar 1, 2005

Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1