Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3246

Опубликовано: 11 авг. 2015
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:libuser:*:*:*:*:*:*:*:*
Версия до 0.56.13-5 (включая)
cpe:2.3:a:redhat:libuser:0.60-1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:libuser:0.60-6:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.06797
Низкий

7.2 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 11 лет назад

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

redhat
около 11 лет назад

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

debian
почти 11 лет назад

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhe ...

github
около 4 лет назад

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

oracle-oval
около 11 лет назад

ELSA-2015-1483: libuser security update (IMPORTANT)

EPSS

Процентиль: 93%
0.06797
Низкий

7.2 High

CVSS2

Дефекты

CWE-264