CVE-2024-56433

CVSS 3.1 Score 3.6 of 10 (low)

Details

Published Dec 26, 2024
CWE ID 1188

Summary

CVE-2024-56433 affects shadow-utils (shadow) versions 4.4 to 4.17.0, where a default behavior in the /etc/subuid file sets user IDs (uids) that can overlap with locally administered networks. This conflict may result in account takeover, as users with conflicting uids can gain access to NFS home directories or local resources via newuidmap. System administrators are advised against assigning uids within local networks that fall within the range of possible uids in /etc/subuid.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share