LWN.net Logo

shadow: privilege escalation

Package(s):shadow CVE #(s):CVE-2011-0721
Created:February 16, 2011 Updated:March 28, 2011
Description: The chfn and chsh utilities fail to properly sanitize user input, allowing the injection of newlines into the password file; that, in turn, allows the addition of arbitrary entries.
Alerts:
Slackware SSA:2011-086-03 2011-03-28
Pardus 2011-47 2011-02-21
Debian DSA-2164-1 2011-02-16
Ubuntu USN-1065-1 2011-02-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds