CVE-2011-0721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/02/2011
Last modified:
11/04/2025

Description

Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:debian:shadow:1\:4.1.4:*:*:*:*:*:*:*