libuser before 0.56.13-8 and 0.60 before 0.60-7, as used...
High severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Aug 26, 2026
Description
Published by the National Vulnerability Database
Aug 11, 2015
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Aug 26, 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
References