PT-2015-6121 · Libuser+2 · Libuser+2

Published

2015-07-23

·

Updated

2023-02-13

·

CVE-2015-3245

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libuser versions prior to 0.56.13-8 libuser versions prior to 0.60-7
Description The issue allows local users to cause a denial of service, resulting in /etc/passwd corruption, via a newline character in the GECOS field. A local, authenticated user could use this flaw to corrupt the /etc/passwd file, resulting in a denial-of-service on the system.
Recommendations For libuser versions prior to 0.56.13-8, update to version 0.56.13-8 or later to resolve the issue. For libuser versions prior to 0.60-7, update to version 0.60-7 or later to resolve the issue. As a temporary workaround, consider restricting access to the chfn function to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CESA-2015_1482
CESA-2015_1483
CVE-2015-3245
DLA-468-1
ELSA-2015-1482
ELSA-2015-1483
MGASA-2015-0278
OPENSUSE-SU-2015_1332-1
RHSA-2015:1482
RHSA-2015:1483
RHSA-2015_1482
RHSA-2015_1483

Affected Products

Centos
Red Hat
Libuser