MGASA-2015-0278
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 24 Jul 2015, 16:36
Last modified:16 Apr 2026, 06:22
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
24 Jul 2015, 16:36
Published
Vulnerability first disclosed
16 Apr 2026, 06:22
Last Modified
Vulnerability information updated
Description
Updated libuser package fixes security vulnerabilities Two flaws were found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root (CVE-2015-3245, CVE-2015-3246).
Affected Systems
- mageia•libuser
< 0.60-2.1.mga4
- mageia•libuser
< 0.60-5.1.mga5
References (6)
- https://advisories.mageia.org/MGASA-2015-0278.html
- https://bugs.mageia.org/show_bug.cgi?id=16459
- https://securityblog.redhat.com/2015/07/23/libuser-vulnerabilities/
- https://access.redhat.com/articles/1537873
- http://openwall.com/lists/oss-security/2015/07/23/16
- https://rhn.redhat.com/errata/RHSA-2015-1483.html