Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-3503. PoCs published by Hunger.
AI-analyzed exploit summary This exploit leverages a local privilege escalation vulnerability in SuSE Linux's 'chfn' utility by manipulating the GECOS field to create a root user entry in /etc/passwd. It then uses 'su' to switch to the newly created root user.
Description
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
Exploits (1)
This exploit leverages a local privilege escalation vulnerability in SuSE Linux's 'chfn' utility by manipulating the GECOS field to create a root user entry in /etc/passwd. It then uses 'su' to switch to the newly created root user.