First published: Tue Aug 11 2015(Updated: )
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libuser | <=0.56.13-5 | |
Redhat Libuser | =0.60-1 | |
Redhat Libuser | =0.60-2 | |
Redhat Libuser | =0.60-3 | |
Redhat Libuser | =0.60-4 | |
Redhat Libuser | =0.60-5 | |
Redhat Libuser | =0.60-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.