Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSystemd Project Systemd
APPSystemd Project223
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
Related vulnerabilities
CVE-2022-2526CRITICAL9.8PL ✓same product
Use-after-free w systemd resolved-dns-stream.c (CVE-2022-2526)
CVE-2018-21029CRITICAL9.8PL ✓same product
Systemd — brak walidacji SNI i nazwy hosta w DNS over TLS (DoT)
CVE-2017-1000082CRITICAL9.8PL ✓same product
Eskalacja uprawnień do root w systemd przez błąd parsowania nazwy użytkownika
CVE-2023-26604HIGH7.8same product
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., pl...
CVE-2020-1712HIGH7.8same product
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit qu...