CVE-2015-3246

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
redhatlibuser
𝑥
≤ 0.56.13-5
redhatlibuser
0.60-1
redhatlibuser
0.60-2
redhatlibuser
0.60-3
redhatlibuser
0.60-4
redhatlibuser
0.60-5
redhatlibuser
0.60-6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libuser
bullseye
1:0.62~dfsg-0.4
fixed
jessie
no-dsa
bookworm
1:0.64~dfsg-1
fixed
sid
1:0.64~dfsg-2
fixed
trixie
1:0.64~dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libuser
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
needed
wily
ignored
vivid
ignored
trusty
Fixed 1:0.56.9.dfsg.1-1.2ubuntu2+esm1
released
precise
ignored
Common Weakness Enumeration