CVE-2016-6252

EUVD-2016-7182
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
Affected Products (NVD)
VendorProductVersion
shadow_projectshadow
4.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
shadow
bookworm
1:4.13+dfsg1-1
fixed
bullseye
1:4.8.1-1
fixed
sid
1:4.16.0-4
fixed
trixie
1:4.16.0-4
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
shadow
precise
ignored
trusty
Fixed 1:4.1.5.1-1ubuntu9.4
released
wily
ignored
xenial
Fixed 1:4.2-3.1ubuntu5.2
released
yakkety
Fixed 1:4.2-3.2ubuntu1.16.10.1
released
zesty
Fixed 1:4.2-3.2ubuntu1.17.04.1
released