PT-2015-6121 · Libuser+2 · Libuser+2

CVE-2015-3245

·

Published

2015-07-23

·

Updated

2026-08-27

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libuser versions prior to 0.56.13-8 libuser versions prior to 0.60-7
Description The issue allows local users to cause a denial of service, resulting in /etc/passwd corruption, via a newline character in the GECOS field. A local, authenticated user could use this flaw to corrupt the /etc/passwd file, resulting in a denial-of-service on the system.
Recommendations For libuser versions prior to 0.56.13-8, update to version 0.56.13-8 or later to resolve the issue. For libuser versions prior to 0.60-7, update to version 0.60-7 or later to resolve the issue. As a temporary workaround, consider restricting access to the chfn function to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_1482
CESA-2015_1483
CVE-2015-3245
DLA-468-1
ELSA-2015-1482
ELSA-2015-1483
MGASA-2015-0278
OPENSUSE-SU-2015_1332-1
RHSA-2015:1482
RHSA-2015:1483
RHSA-2015_1482
RHSA-2015_1483

Affected Products

Centos
Red Hat
Libuser