Back

HIGH KEV

libuser: Security flaw in handling /etc/passwd file

Published Aug 11, 2015 ·Due Sep 9, 2026

Description

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Affected products

Remediation

Red Hat statement

This issue affects the versions of libuser as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This vulnerability has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Red Hat mitigation

Add pam_warn and pam_deny rules to /etc/pam.d/chfn and /etc/pam.d/chsh to prevent non-root users from using this functionality. With these edits, the files should contain: auth sufficient pam_rootok.so auth required pam_warn.so auth required pam_deny.so auth include system-auth account include system-auth password include system-auth session include system-auth After these changes, attempts by unprivileged users to use chfn and chsh (and the respective functionality in the userhelper program) will fail, and will be logged (by default in /var/log/secure).

Metrics

Weaknesses (2)

References (17)

Change history (18)
  1. NVD
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CVSS score changed from 5.1 to 7.4
  2. CISA ADP
    • SSVC technical impact changed from partial to total
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CVSS score changed from 5.1 to 7.4
  3. CISA ADP
    • SSVC technical impact changed from total to partial
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H to CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CVSS score changed from 7.4 to 5.1
  4. CISA ADP
    • SSVC technical impact changed from partial to total
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H to CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CVSS score changed from 5.1 to 7.4
  5. CISA ADP
    • SSVC technical impact changed from total to partial
  6. CISA ADP
    • SSVC technical impact changed from partial to total
  7. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 11, 2015
Updated Oct 1, 2026
Reserved Apr 10, 2015
CISA Vulnrichment
Updated Aug 27, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity Important
Public date Jul 23, 2015