{"id":"UBUNTU-CVE-2021-40084","details":"opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.","modified":"2026-05-20T16:05:12.396899461Z","published":"2021-08-25T01:15:00Z","upstream":["CVE-2021-40084"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-40084"},{"type":"REPORT","url":"https://github.com/artix-linux/opensysusers/releases"},{"type":"REPORT","url":"https://bugs.debian.org/992058"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-40084"}],"affected":[{"package":{"name":"opensysusers","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/opensysusers?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.5.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.5.1-1","binary_name":"opensysusers"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40084.json"}},{"package":{"name":"opensysusers","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/opensysusers?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6-2","0.6-3"],"ecosystem_specific":{"binaries":[{"binary_name":"opensysusers","binary_version":"0.6-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40084.json"}},{"package":{"name":"opensysusers","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/opensysusers?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.3-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.7.3-2","binary_name":"opensysusers"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40084.json"}},{"package":{"name":"opensysusers","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/opensysusers?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.3-4.1","0.7.3-5"],"ecosystem_specific":{"binaries":[{"binary_name":"opensysusers","binary_version":"0.7.3-5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40084.json"}},{"package":{"name":"opensysusers","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/opensysusers?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.3-5","0.7.3-5.1"],"ecosystem_specific":{"binaries":[{"binary_name":"opensysusers","binary_version":"0.7.3-5.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40084.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}]}