libuser: Security flaw in handling /etc/passwd file
Published Aug 11, 2015 ·Due Sep 9, 2026
7.4
HIGHCVSS 3.1
EPSS 8.80%
Description
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Affected products
No data.
Configuration 1
- 5.0
- 6.0
- 7.0
Configuration 3
- < 0.56.13-8
- ≥ 0.60 · < 0.60-7
No data.
Red Hat Enterprise Linux 6
libuser-0:0.56.13-8.el6_7
Fixed · RHSA-2015:1482
Red Hat Enterprise Linux 7
libuser-0:0.60-7.ael7b_1
Fixed · RHSA-2015:1483
Red Hat Enterprise Linux 5
libuser
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libuser-0:0.56.13-8.el6_7 | Fixed | RHSA-2015:1482 |
| Red Hat Enterprise Linux 7 | libuser-0:0.60-7.ael7b_1 | Fixed | RHSA-2015:1483 |
| Red Hat Enterprise Linux 5 | libuser | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of libuser as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This vulnerability has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
Add pam_warn and pam_deny rules to /etc/pam.d/chfn and /etc/pam.d/chsh to prevent non-root users from using this functionality. With these edits, the files should contain: auth sufficient pam_rootok.so auth required pam_warn.so auth required pam_deny.so auth include system-auth account include system-auth password include system-auth session include system-auth After these changes, attempts by unprivileged users to use chfn and chsh (and the respective functionality in the userhelper program) will fail, and will be logged (by default in /var/log/secure).
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Aug 26, 2026
Patch Due
Sep 9, 2026
Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.80% (0.08799) | 95.03th | v5 (v2026.06.15) |
| Aug 27, 2026 | 8.80% (0.08799) | 94.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.85% (0.06853) | 93.19th | v5 (v2026.06.15) |
| Jun 6, 2026 | 19.63% (0.19626) | 95.55th | v4 (v2025.03.14) |
| Apr 7, 2026 | 21.42% (0.21424) | 95.69th | v4 (v2025.03.14) |
| Mar 2, 2026 | 19.61% (0.19605) | 95.33th | v4 (v2025.03.14) |
| Dec 21, 2025 | 21.42% (0.21424) | 95.51th | v4 (v2025.03.14) |
| Oct 12, 2025 | 18.92% (0.18917) | 95.00th | v4 (v2025.03.14) |
| Oct 2, 2025 | 16.40% (0.16399) | 94.66th | v4 (v2025.03.14) |
| Sep 24, 2025 | 17.90% (0.17899) | 94.92th | v4 (v2025.03.14) |
| Jun 22, 2025 | 20.31% (0.20312) | 95.20th | v4 (v2025.03.14) |
| Jun 8, 2025 | 18.56% (0.18560) | 94.90th | v4 (v2025.03.14) |
| May 19, 2025 | 19.93% (0.19927) | 95.13th | v4 (v2025.03.14) |
| Mar 30, 2025 | 21.77% (0.21766) | 95.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 18.05% (0.18049) | 92.04th | v4 (v2025.03.14) |
| Mar 21, 2025 | 21.77% (0.21766) | 95.28th | v4 (v2025.03.14) |
| Mar 19, 2025 | 27.53% (0.27534) | 95.81th | v4 (v2025.03.14) |
| Mar 17, 2025 | 26.45% (0.26445) | 95.89th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.28% (0.01282) | 67.79th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.55% (0.01547) | 74.40th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (17)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html vendor-advisoryx_refsource_FEDORABroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html vendor-advisoryx_refsource_FEDORABroken Link
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1482.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1483.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/bid/76022 vdb-entryx_refsource_BIDThird Party Advisory
- http://www.securitytracker.com/id/1033040 vdb-entryx_refsource_SECTRACKThird Party Advisory
- https://access.redhat.com/articles/1537873 x_refsource_CONFIRMMitigationVendor Advisory
- https://access.redhat.com/security/cve/CVE-2015-3246 Vendor Advisory
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/ third-party-advisoryThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1233052 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-3246
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2015-3246
- https://www.exploit-db.com/exploits/44633/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt x_refsource_MISCExploit
Change history (18)
- NVD
- CVSS severity changed from MEDIUM to
HIGH MEDIUM → HIGH
- CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H → CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS score changed from 5.1 to
7.4 5.1 → 7.4
- CVSS severity changed from MEDIUM to
HIGH
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- CVSS severity changed from MEDIUM to
HIGH MEDIUM → HIGH
- CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H → CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS score changed from 5.1 to
7.4 5.1 → 7.4
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- CVSS severity changed from HIGH to
MEDIUM HIGH → MEDIUM
- CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H to
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H → CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS score changed from 7.4 to
5.1 7.4 → 5.1
- SSVC technical impact changed from total to
partial
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- CVSS severity changed from MEDIUM to
HIGH MEDIUM → HIGH
- CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H → CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS score changed from 5.1 to
7.4 5.1 → 7.4
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC technical impact changed from total to
partial
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC technical impact changed from total to
partial