Record summary

CVE-2005-3503 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.

Description

chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBLinux chfn (SuSE 9.3/10) - Local Privilege EscalationExploitDB exploitby HungerNot analyzed1 file
ExploitDB

PoC details

References

5