CVE-2015-3245
libuser <0.56.13-8 & 0.60 - DoS
Title source: llmDescription
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/44633
metasploit
WORKING POC
GREAT
by Qualys, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/libuser_roothelper_priv_esc.rb
References (9)
Scores
EPSS
0.1116
EPSS Percentile
93.5%
Details
CWE
CWE-20
Status
published
Products (7)
redhat/libuser
0.60-1
redhat/libuser
0.60-2
redhat/libuser
0.60-3
redhat/libuser
0.60-4
redhat/libuser
0.60-5
redhat/libuser
0.60-6
redhat/libuser
< 0.56.13-5
Published
Aug 11, 2015
Tracked Since
Feb 18, 2026