vulnti.work

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (incon…

Medium CVSS 5.1 Listed in CISA KEV
CVECVE-2015-3246
First seen2026-08-26 19:15 UTC
Disclosed2015-08-11 14:59 UTC
Last updated2026-08-26 21:15 UTC
Channel statusauto

Summary

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • :
  • Red Hat:Libuser
  • :
  • :
  • :

Sources

  • NVD DATABASE
  • CISA KEV DATABASE

Original Links

Timeline

  1. nvd_ingest NVD
  2. kev_ingest CISA KEV