CVE-2015-3245

libuser <0.56.13-8 & 0.60 - DoS

Title source: llm

Description

Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/44633
exploitdb WRITEUP
doslinux
https://www.exploit-db.com/exploits/37706
metasploit WORKING POC GREAT
by Qualys, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/libuser_roothelper_priv_esc.rb

Scores

EPSS 0.1116
EPSS Percentile 93.5%

Details

CWE
CWE-20
Status published
Products (7)
redhat/libuser 0.60-1
redhat/libuser 0.60-2
redhat/libuser 0.60-3
redhat/libuser 0.60-4
redhat/libuser 0.60-5
redhat/libuser 0.60-6
redhat/libuser < 0.56.13-5
Published Aug 11, 2015
Tracked Since Feb 18, 2026