CVE-2016-6252

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
shadow_projectshadow
4.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
shadow
bullseye
1:4.8.1-1
fixed
wheezy
not-affected
bookworm
1:4.13+dfsg1-1
fixed
sid
1:4.16.0-4
fixed
trixie
1:4.16.0-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
shadow
zesty
Fixed 1:4.2-3.2ubuntu1.17.04.1
released
yakkety
Fixed 1:4.2-3.2ubuntu1.16.10.1
released
xenial
Fixed 1:4.2-3.1ubuntu5.2
released
wily
ignored
trusty
Fixed 1:4.1.5.1-1ubuntu9.4
released
precise
ignored