PT-2026-84129 · Unknown · Yast2-Users
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
yast2-users versions prior to 5.0.9
Description
An OS command injection issue exists when displaying the Password Settings tab of a user. The
get password term() function in src/include/users/dialogs.rb retrieves the shadowLastChange and shadowExpire fields using GetString(), which lacks numeric validation. These strings are then passed to the format days after epoch() helper, which interpolates the values into a shell command executed via Ruby backticks without proper quoting or escaping. This allows an administrator managing users via an external or federated LDAP directory to trigger root command execution simply by viewing or editing a user entry.Recommendations
Update yast2-users to version 5.0.9 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yast2-Users