MGASA-2015-0278
Dashboard / Vulnerabilities / MGASA-2015-0278
Summary: Updated libuser package fixes security vulnerabilities
Details: Two flaws were found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root (CVE-2015-3245, CVE-2015-3246).
References: https://advisories.mageia.org/MGASA-2015-0278.html, https://bugs.mageia.org/show_bug.cgi?id=16459, https://securityblog.redhat.com/2015/07/23/libuser-vulnerabilities/, https://access.redhat.com/articles/1537873, http://openwall.com/lists/oss-security/2015/07/23/16, https://rhn.redhat.com/errata/RHSA-2015-1483.html
Affected packages
Package
Name: libuser
Purl: pkg:rpm/mageia/libuser?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
