libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libuser | Libuser_project | 0.57 (including) | 0.57 (including) |
Libuser | Libuser_project | 0.58 (including) | 0.58 (including) |
Libuser | Ubuntu | esm-infra-legacy/trusty | * |
Libuser | Ubuntu | hardy | * |
Libuser | Ubuntu | lucid | * |
Libuser | Ubuntu | oneiric | * |
Libuser | Ubuntu | precise | * |
Libuser | Ubuntu | quantal | * |
Libuser | Ubuntu | raring | * |
Libuser | Ubuntu | saucy | * |
Libuser | Ubuntu | trusty | * |
Libuser | Ubuntu | trusty/esm | * |
Libuser | Ubuntu | upstream | * |
Libuser | Ubuntu | utopic | * |