PT-2015-6122 · Libuser+3 · Libuser+3

CVE-2015-3246

·

Published

2015-07-23

·

Updated

2026-08-27

CVSS v3.1

5.1

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libuser versions prior to 0.56.13-8 libuser version 0.60 prior to 0.60-7
Description The issue allows local users to cause a denial of service by causing an error during the modification of /etc/passwd, resulting in an inconsistent file state. This can be combined with another issue to potentially gain privileges.
Recommendations For libuser versions prior to 0.56.13-8, update to version 0.56.13-8 or later. For libuser version 0.60 prior to 0.60-7, update to version 0.60-7 or later.

Exploit

Fix

DoS

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2015_1482
CESA-2015_1483
CVE-2015-3246
DLA-468-1
MGASA-2015-0278
OPENSUSE-SU-2015_1332-1
RHSA-2015:1482
RHSA-2015:1483
RHSA-2015_1482
RHSA-2015_1483

Affected Products

Centos
Red Hat
Suse
Libuser