CVE Vulnerabilities

CVE-2017-1000082

Improper Privilege Management

Published: Jul 07, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.2 MODERATE
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. 0day), running the service in question with root privileges rather than the user intended.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
SystemdSystemd_project229 (including)234 (excluding)
SystemdUbuntuesm-infra/xenial*
SystemdUbuntuupstream*
SystemdUbuntuvivid/ubuntu-core*
SystemdUbuntuxenial*
SystemdUbuntuyakkety*
SystemdUbuntuzesty*

Potential Mitigations

References