CVE-2017-12424

critical
Published 2017-08-04 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-12424

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-12424.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/shadow-maint/shadow/commit/954e3d2e7113e9ac06632aee3c69b8d818cc8952

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debian9.0affected
debian debianbookwormfixed1:4.5-1
debian debianbullseyefixed1:4.5-1
debian debianforkyfixed1:4.5-1
debian debiansidfixed1:4.5-1
debian debiantrixiefixed1:4.5-1

Application impact

VendorProductVersionsFixed
shadow_projectshadow{"endExcluding":"4.5"}4.5

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.