Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3245

Опубликовано: 11 авг. 2015
Источник: nvd
CVSS2: 2.1
EPSS Средний

Описание

Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:libuser:*:*:*:*:*:*:*:*
Версия до 0.56.13-5 (включая)
cpe:2.3:a:redhat:libuser:0.60-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-6:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.15421
Средний

2.1 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 10 лет назад

Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.

redhat
около 10 лет назад

Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.

debian
около 10 лет назад

Incomplete blacklist vulnerability in the chfn function in libuser bef ...

github
больше 3 лет назад

Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.

oracle-oval
около 10 лет назад

ELSA-2015-1483: libuser security update (IMPORTANT)

EPSS

Процентиль: 94%
0.15421
Средний

2.1 Low

CVSS2

Дефекты

CWE-20