CVE Vulnerabilities

CVE-2017-1000082

Improper Privilege Management

Published: Jul 07, 2017 | Modified: Oct 11, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.2 MODERATE
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Ubuntu
LOW

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. 0day), running the service in question with root privileges rather than the user intended.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Systemd Systemd_project 229 (including) 234 (excluding)
Systemd Ubuntu esm-infra/xenial *
Systemd Ubuntu upstream *
Systemd Ubuntu vivid/ubuntu-core *
Systemd Ubuntu xenial *
Systemd Ubuntu yakkety *
Systemd Ubuntu zesty *

Potential Mitigations

References