Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0721

22
FAUCET Score

CVE-2011-0721 describes multiple CRLF injection vulnerabilities within the chfn and chsh utilities in shadow version 1:4.1.4, specifically affecting Debian systems. An attacker can exploit these flaws by manipulating the GECOS field to inject new user or group entries into the /etc/passwd file. This vulnerability has a CVSS score of 6.4, indicating a medium severity with low attack complexity and potential for partial integrity and availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1\:4.1.4CPE matchmatch criteria
cpe:2.3:a:debian:shadow:1\:4.1.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.4MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.31%
Probability of exploitation in next 30 days
EPSS Percentile
81.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0231 is in the 72nd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2011-0721Moderate

shadow: Multiple CRLF injections in chfn and chsh

Feb 15, 2011

References

osvdb.org / 70895
secunia.com / advisories/42505
Vendor Advisory
secunia.com / advisories/43345
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/65564
slackware.com / security/viewer.php
debian.org / security/2011/dsa-2164
securityfocus.com / bid/46426
ubuntu.com / usn/USN-1065-1
vupen.com / english/advisories/2011/0396
Vendor Advisory
vupen.com / english/advisories/2011/0398
Vendor Advisory
vupen.com / english/advisories/2011/0773