NVD
- Id
- 25134
- Name
- CVE-2015-3245
- Description
- Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.
- Reject
- CVSS Version
- 2
- CVSS Score
- 2.1
- Severity
- Low
- CVSS Base Score
- 2.1
- CVSS Impact Subscore
- 2.9
- CVSS Exploit Subscore
- 3.9
- CVSS Vector
- (AV:L/AC:L/Au:N/C:N/I:N/A:P)
- Pub Date
- 2017-01-19
- Published
- 2015-08-11
- Modified Date
- 2016-12-23
- Seq
- 2015-3245