CVE-2015-3246

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:libuser:0.60-6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-1:*:*:*:*:*:*:*

Information

Published : 2015-08-11 07:59

Updated : 2018-05-19 18:29


NVD link : CVE-2015-3246

Mitre link : CVE-2015-3246


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

redhat

  • libuser