PT-2015-6122 · Libuser+3 · Libuser+3

Published

2015-07-23

·

Updated

2018-05-20

·

CVE-2015-3246

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libuser versions prior to 0.56.13-8 libuser version 0.60 prior to 0.60-7
Description The issue allows local users to cause a denial of service by causing an error during the modification of /etc/passwd, resulting in an inconsistent file state. This can be combined with another issue to potentially gain privileges.
Recommendations For libuser versions prior to 0.56.13-8, update to version 0.56.13-8 or later. For libuser version 0.60 prior to 0.60-7, update to version 0.60-7 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_1482
CESA-2015_1483
CVE-2015-3246
DLA-468-1
MGASA-2015-0278
OPENSUSE-SU-2015_1332-1
RHSA-2015:1482
RHSA-2015:1483
RHSA-2015_1482
RHSA-2015_1483

Affected Products

Centos
Red Hat
Suse
Libuser