Overview
Original source datalibuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Affected products and scope
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Technical details
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Exploitability
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Technical impact
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Business impact
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Remediation
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Detection
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Other references
- http://www.securityfocus.com/bid/76022
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
- https://www.exploit-db.com/exploits/44633/
- https://access.redhat.com/articles/1537873
- http://rhn.redhat.com/errata/RHSA-2015-1482.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
- https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
- http://www.securitytracker.com/id/1033040
- http://rhn.redhat.com/errata/RHSA-2015-1483.html
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246
