Vulnerabilities
Vulnerable Software
Libuser Project:  Security Vulnerabilities
libuser has information disclosure when moving user's home directory
CVSS Score
5.5
EPSS Score
0.004
Published
2019-11-25
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
CVSS Score
6.3
EPSS Score
0.003
Published
2019-11-25
CVE-2015-3246
Known exploited
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
CVSS Score
5.1
EPSS Score
0.088
Published
2015-08-11


Contact Us

Shodan ® - All rights reserved