17469Third-party advisory
http://secunia.com/advisories/17469 CVE-2005-3503
Linux chfn (SuSE 9.3/10) - Local Privilege Escalation
Record summary
CVE-2005-3503 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinux chfn (SuSE 9.3/10) - Local Privilege EscalationExploitDB exploitby HungerNot analyzed1 file
References
520525vdb entry
http://www.osvdb.org/20525 SUSE-SA:2005:064Vendor advisory
http://www.securityfocus.com/archive/1/415725/30/0/threaded 15314vdb entry
http://www.securityfocus.com/bid/15314 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-3503