libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
2015-08-11T14:59:07.040
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | libuser | ≤ 0.56.13-5 | Yes |
Application | redhat | libuser | 0.60-1 | Yes |
Application | redhat | libuser | 0.60-2 | Yes |
Application | redhat | libuser | 0.60-3 | Yes |
Application | redhat | libuser | 0.60-4 | Yes |
Application | redhat | libuser | 0.60-5 | Yes |
Application | redhat | libuser | 0.60-6 | Yes |