CVE Vulnerabilities

CVE-2015-3246

Published: Aug 11, 2015 | Modified: May 20, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:L/AC:L/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Affected Software

Name Vendor Start Version End Version
Libuser Redhat * 0.56.13-5 (including)
Libuser Redhat 0.60-1 (including) 0.60-1 (including)
Libuser Redhat 0.60-2 (including) 0.60-2 (including)
Libuser Redhat 0.60-3 (including) 0.60-3 (including)
Libuser Redhat 0.60-4 (including) 0.60-4 (including)
Libuser Redhat 0.60-5 (including) 0.60-5 (including)
Libuser Redhat 0.60-6 (including) 0.60-6 (including)
Red Hat Enterprise Linux 6 RedHat libuser-0:0.56.13-8.el6_7 *
Red Hat Enterprise Linux 7 RedHat libuser-0:0.60-7.el7_1 *
Libuser Ubuntu esm-apps/xenial *
Libuser Ubuntu precise *
Libuser Ubuntu trusty *
Libuser Ubuntu trusty/esm *
Libuser Ubuntu upstream *
Libuser Ubuntu vivid *
Libuser Ubuntu wily *
Libuser Ubuntu xenial *

References