Bug#940577: adduser: [SECURITY] command injection in deluser program when invoking crontab with malicious username

2022-04-09 Thread Haoxi Tan
Hi there, Has a Debian CVE been filed for this bug? Might be present in other distros too, so could be useful to publish one. Thanks, Haoxi On Tue, 8 Mar 2022 at 06:08, Marc Haber wrote: > Control: outlook -1 write test case, fix issue > thanks > > On Tue, Sep 17, 2019 at 01:22:46PM +,

Bug#940577: adduser: [SECURITY] command injection in deluser program when invoking crontab with malicious username

2022-03-07 Thread Marc Haber
Control: outlook -1 write test case, fix issue thanks On Tue, Sep 17, 2019 at 01:22:46PM +, Haoxi Tan wrote: > A command injection vulnerability has been found in the deluser > program in the adduser package. Embarrassing. My own bug. system() should never be used with a string, just with an

Bug#940577: adduser: [SECURITY] command injection in deluser program when invoking crontab with malicious username

2019-09-17 Thread Haoxi Tan
Package: adduser Version: 3.118 Severity: important Dear Maintainer, A command injection vulnerability has been found in the deluser program in the adduser package. When deleteing a user via deluser with dangerous characters in its name (such as / and ;), the commands injected are interpreted