CVE Vulnerabilities

CVE-2015-3246

Published: Aug 11, 2015 | Modified: May 20, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Affected Software

Name Vendor Start Version End Version
Libuser Redhat 0.60-3 0.60-3
Libuser Redhat * 0.56.13-5
Libuser Redhat 0.60-1 0.60-1
Libuser Redhat 0.60-6 0.60-6
Libuser Redhat 0.60-2 0.60-2
Libuser Redhat 0.60-5 0.60-5
Libuser Redhat 0.60-4 0.60-4

References