Giới thiệu chung
Dữ liệu gốclibuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Sản phẩm và phạm vi ảnh hưởng
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Chi tiết kỹ thuật
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Khả năng khai thác
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Tác động kỹ thuật
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Tác động đến tổ chức
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Cách khắc phục
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Cách phát hiện
CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Tham chiếu khác
- http://www.securityfocus.com/bid/76022
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
- https://www.exploit-db.com/exploits/44633/
- https://access.redhat.com/articles/1537873
- http://rhn.redhat.com/errata/RHSA-2015-1482.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
- https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
- http://www.securitytracker.com/id/1033040
- http://rhn.redhat.com/errata/RHSA-2015-1483.html
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246
