[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2015-572 --- usermode libuser

ID: oval:org.secpod.oval:def:1200030Date: (C)2015-12-30   (M)2023-07-28
Class: PATCHFamily: unix




It was found that libuser, as used in the chfn userhelper functionality, does not properly filter out newline characters, which allows an authenticated local attacker to corrupt the /etc/passwd file and cause denial-of-service against the system. A flaw was found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root

Platform:
Amazon Linux AMI
Product:
usermode
libuser
Reference:
ALAS-2015-572
CVE-2015-3245
CVE-2015-3246
CVE    2
CVE-2015-3246
CVE-2015-3245
CPE    3
cpe:/o:amazon:linux
cpe:/a:usermode:usermode
cpe:/a:miloslav_trmac:libuser

© SecPod Technologies