libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libuser | Redhat | * | 0.56.13-5 (including) |
Libuser | Redhat | 0.60-1 (including) | 0.60-1 (including) |
Libuser | Redhat | 0.60-2 (including) | 0.60-2 (including) |
Libuser | Redhat | 0.60-3 (including) | 0.60-3 (including) |
Libuser | Redhat | 0.60-4 (including) | 0.60-4 (including) |
Libuser | Redhat | 0.60-5 (including) | 0.60-5 (including) |
Libuser | Redhat | 0.60-6 (including) | 0.60-6 (including) |
Red Hat Enterprise Linux 6 | RedHat | libuser-0:0.56.13-8.el6_7 | * |
Red Hat Enterprise Linux 7 | RedHat | libuser-0:0.60-7.el7_1 | * |
Libuser | Ubuntu | esm-apps/xenial | * |
Libuser | Ubuntu | precise | * |
Libuser | Ubuntu | trusty | * |
Libuser | Ubuntu | trusty/esm | * |
Libuser | Ubuntu | upstream | * |
Libuser | Ubuntu | vivid | * |
Libuser | Ubuntu | wily | * |
Libuser | Ubuntu | xenial | * |