PT-2015-6121 · Libuser+2 · Libuser+2
CVE-2015-3245
·
Publicado
2015-07-23
·
Atualizado
2026-08-27
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libuser versions prior to 0.56.13-8
libuser versions prior to 0.60-7
Description
The issue allows local users to cause a denial of service, resulting in /etc/passwd corruption, via a newline character in the GECOS field. A local, authenticated user could use this flaw to corrupt the /etc/passwd file, resulting in a denial-of-service on the system.
Recommendations
For libuser versions prior to 0.56.13-8, update to version 0.56.13-8 or later to resolve the issue.
For libuser versions prior to 0.60-7, update to version 0.60-7 or later to resolve the issue.
As a temporary workaround, consider restricting access to the chfn function to minimize the risk of exploitation.
Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Libuser