CVE-2017-1000082

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
07/07/2017
Last modified:
20/04/2025

Description

systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* 229 (including) 234 (excluding)