PublicDateAtUSN: 2017-02-17 Candidate: CVE-2016-6252 PublicDate: 2017-02-17 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6252 https://ubuntu.com/security/notices/USN-3276-1 Description: Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap. Ubuntu-Description: Notes: leosilva> shadow version for precise-esm and vivid/ubuntu-core doesn't use leosilva> newuidmap binaries neither does any privileged access that makes leosilva> this fix necessary. Bugs: https://bugzilla.suse.com/show_bug.cgi?id=979282 https://github.com/shadow-maint/shadow/issues/27 Priority: medium Discovered-by: Sebastian Krahmer Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_shadow: vendor: https://bugzilla.suse.com/attachment.cgi?id=684679&action=diff upstream: https://github.com/shadow-maint/shadow/commit/1d5a926cc2d6078d23a96222b1ef3e558724dad1 upstream_shadow: needs-triage precise_shadow: ignored (reached end-of-life) precise/esm_shadow: not-affected trusty_shadow: released (1:4.1.5.1-1ubuntu9.4) trusty/esm_shadow: released (1:4.1.5.1-1ubuntu9.4) vivid/stable-phone-overlay_shadow: ignored (reached end-of-life) vivid/ubuntu-core_shadow: not-affected wily_shadow: ignored (reached end-of-life) xenial_shadow: released (1:4.2-3.1ubuntu5.2) esm-infra/xenial_shadow: released (1:4.2-3.1ubuntu5.2) yakkety_shadow: released (1:4.2-3.2ubuntu1.16.10.1) zesty_shadow: released (1:4.2-3.2ubuntu1.17.04.1) devel_shadow: released (1:4.2-3.2ubuntu2)