Bug 1468427 (CVE-2017-1000082)

Summary: CVE-2017-1000082 systemd: fails to parse usernames that start with digits
Product: [Other] Security Response Reporter: Doran Moppert <dmoppert>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: johannbg, lnykryn, msekleta, muadda, ssahani, s, systemd-maint-list, systemd-maint, zbyszek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20170707,reported=20170707,source=oss-security,cvss3=7.2/CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H,cwe=CWE-20,rhel-7/systemd=notaffected,fedora-all/systemd=affected
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-07-07 04:53:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 1468430    
Bug Blocks: 1467225    

Description Doran Moppert 2017-07-07 04:30:28 UTC
Systemd version 323 rejects usernames starting with a digit (eg "0day"),
running the service with root privileges even though a corresponding user
exists.

Upstream bug:

https://github.com/systemd/systemd/issues/6237

oss-sec discussion:

http://www.openwall.com/lists/oss-security/2017/07/02/1

Comment 1 Doran Moppert 2017-07-07 04:40:47 UTC
This issue seems to have been introduced since systemd-229.  Neither EL7 nor Fedora 24 is affected - not sure about 231/233.

For an attacker to exploit this they would need to influence the creation of a user and associated unit file on the system.

Comment 2 Doran Moppert 2017-07-07 04:52:25 UTC
Created systemd tracking bugs for this issue:

Affects: fedora-all [bug 1468430]

Comment 3 Doran Moppert 2017-07-10 06:45:23 UTC
Statement:

For more information on the impact of numeric usernames in Red Hat Enterprise Linux, please see https://access.redhat.com/solutions/3103631