CVE-2015-3246

Aliases:DEBIAN-CVE-2015-3246
Analyzed
Published: 11 Aug 2015, 14:00
Last modified:27 Aug 2026, 03:56

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.2 HIGH
v2.0 (nvd)
EPSS Score
7.09% LOW
7% probability -14.33%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
4 found
Dark Web
Not detected

Timeline

11 Aug 2015, 14:00
Published
Vulnerability first disclosed
26 Aug 2026, 00:00
Added to CISA KEV
Red Hat Libuser Race Condition Vulnerability
27 Aug 2026, 03:56
Last Modified
Vulnerability information updated
09 Sept 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

CVSS Metrics

  • v3.1MEDIUMScore: 5.1CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 7.09% Percentile: 94%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

  • CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition

    The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Affected Systems

  • debianlibuser

    < 1:0.62~dfsg-0.1 | < 1:0.62~dfsg-0.1 | < 1:0.62~dfsg-0.1 | < 1:0.62~dfsg-0.1

  • libuser_projectlibuser

    < 0.56.13-8 | ≥ 0.60, < 0.60-7

  • opensuseopensuse

    13.2

  • redhatenterprise_linux

    5.0 | 6.0 | 7.0

  • redhatlibuser

    ≤ 0.56.13-5 | 0.60-1 | 0.60-2 | 0.60-3 | 0.60-4 | 0.60-5 | 0.60-6

References (13)