CVE-2015-3246
MEDIUM(5.1)KEV — Aktiv ausgenutztCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS 5.1 — Mittel
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
8.8%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
5.1
Technische Schwere
SecBoard-Einordnung
CVE-2015-3246 betrifft die Red Hat libuser Bibliothek, insbesondere in Verbindung mit dem userhelper-Programm im usermode-Paket. Die Schwachstelle ermöglicht es lokalen Benutzern, einen Denial of Service zu verursachen, indem sie den direkten Modifikationsprozess der /etc/passwd-Datei stören. Dies kann zu einem inkonsistenten Dateizustand führen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Betroffene Produkte
- cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
- cpe:2.3:a:libuser_project:libuser:*:*:*:*:*:*:*:*
- cpe:2.3:a:libuser_project:libuser:*:*:*:*:*:*:*:*
Referenzen
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.htm...
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
- http://rhn.redhat.com/errata/RHSA-2015-1482.html
- http://rhn.redhat.com/errata/RHSA-2015-1483.html
- http://www.securityfocus.com/bid/76022
- http://www.securitytracker.com/id/1033040
- https://access.redhat.com/articles/1537873
- https://www.exploit-db.com/exploits/44633/
- https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-...