AllCyberNews

CVE-2015-3246

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CVSS 5.1 medium · n/a n/a · published 2015-08-11

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Coverage 1 source

  1. 2026-08-26 CISA Cybersecurity Advisories high CISA Adds Six Known Exploited Vulnerabilities to Catalog

    CISA added six vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.

Mentioned with

CVE-2015-5287 CVE-2019-1068 CVE-2021-23758 CVE-2022-0995

Also covered