Bug 678897 (CVE-2011-0721)

Summary: CVE-2011-0721 shadow: Multiple CRLF injections in chfn and chsh
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: kzak
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0721
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-10-07 14:21:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2011-02-20 17:02:46 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0721 to
the following vulnerability:

Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in
shadow 1:4.1.4 allow local users to add new users or groups to
/etc/passwd via the GECOS field.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0721
[2] http://www.debian.org/security/2011/dsa-2164
[3] http://www.ubuntu.com/usn/USN-1065-1
[4] http://www.securityfocus.com/bid/46426
[5] http://secunia.com/advisories/42505
[6] http://secunia.com/advisories/43345
[7] http://www.vupen.com/english/advisories/2011/0396
[8] http://www.vupen.com/english/advisories/2011/0398

Comment 1 Jan Lieskovsky 2011-02-20 17:06:21 UTC
This issue did NOT affect the versions of util-linux package, as shipped
with Red Hat Enterprise Linux 3, 4, or 5.

This issue did NOT affect the version of the util-linux-ng package, as shipped
with Red Hat Enterprise Linux 6.

--

This issue did not affect the versions of the util-linux-ng packages, as shipped
with Fedora release of 13 and 14.

Comment 3 Product Security DevOps Team 2020-10-07 14:21:36 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2011-0721