CRITICAL🇵🇱 Wersja polska

CVE-2017-1000082

CVSS 9.8v3.1pub. 2017-07-07upd. 2026-05-13

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Systemd Project Systemd

    APP
    Systemd Project
    229 – 234 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-2526CRITICAL9.8PL ✓same product

Use-after-free w systemd resolved-dns-stream.c (CVE-2022-2526)

CVE-2018-21029CRITICAL9.8PL ✓same product

Systemd — brak walidacji SNI i nazwy hosta w DNS over TLS (DoT)

CVE-2015-7510CRITICAL9.8PL ✓same product

Stack-based buffer overflow w module nss-mymachines systemu systemd

CVE-2023-26604HIGH7.8same product

systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., pl...

CVE-2020-1712HIGH7.8same product

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit qu...