First published: Tue Aug 11 2015(Updated: )
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libuser | <=0.56.13-5 | |
Redhat Libuser | =0.60-1 | |
Redhat Libuser | =0.60-2 | |
Redhat Libuser | =0.60-3 | |
Redhat Libuser | =0.60-4 | |
Redhat Libuser | =0.60-5 | |
Redhat Libuser | =0.60-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.