CVE Vulnerabilities

CVE-2015-3246

Published: Aug 11, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:L/AC:L/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
LibuserRedhat*0.56.13-5 (including)
LibuserRedhat0.60-1 (including)0.60-1 (including)
LibuserRedhat0.60-2 (including)0.60-2 (including)
LibuserRedhat0.60-3 (including)0.60-3 (including)
LibuserRedhat0.60-4 (including)0.60-4 (including)
LibuserRedhat0.60-5 (including)0.60-5 (including)
LibuserRedhat0.60-6 (including)0.60-6 (including)
Red Hat Enterprise Linux 6RedHatlibuser-0:0.56.13-8.el6_7*
Red Hat Enterprise Linux 7RedHatlibuser-0:0.60-7.ael7b_1*
LibuserUbuntuesm-apps/xenial*
LibuserUbuntuesm-infra-legacy/trusty*
LibuserUbuntuplucky*
LibuserUbuntuprecise*
LibuserUbuntutrusty*
LibuserUbuntutrusty/esm*
LibuserUbuntuupstream*
LibuserUbuntuvivid*
LibuserUbuntuwily*
LibuserUbuntuxenial*

References