Shadow Project maintains a focused cryptographic library and toolkit product centered around the Shadow application, with its disclosed vulnerabilities reflecting a pattern of memory-safety and permission-handling issues including buffer bounds violations, integer overflow, injection flaws, and access-control weaknesses. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shadow Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12424CRITICAL In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer o | Aug 4, 2017 | 9.8 | 30 | NO | NO |
CVE-2019-19882HIGH shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Spec | Dec 18, 2019 | 7.8 | 24 | NO | NO |
CVE-2016-6252HIGH Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap. | Feb 17, 2017 | 7.8 | 23 | NO | NO |
CVE-2018-7169MEDIUM An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This | Feb 15, 2018 | 5.3 | 20 | NO | NO |
In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g | Apr 14, 2023 | 3.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shadow Project.
Media articles that mention a CVE ID that affects a product developed by Shadow Project — matched by CVE ID, not by vendor name.