CVE-2021-40084

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
25/08/2021
Last modified:
12/07/2022

Description

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artixlinux:opensysusers:*:*:*:*:*:*:*:* 0.6 (including)