← 戻る
CVE-2015-3246
CISA KEV
medium
CVSS 5.1
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
概要
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
AI要約 openai / gpt-4o
Red Hat libuserにレースコンディションの脆弱性があり、認証されたローカルユーザーが/etc/passwdファイルを破損させ、サービス拒否や特権の昇格を引き起こす可能性があります。この脆弱性はローカル環境で悪用される可能性があり、特に高いリスクを持っています。
❓ 何が問題か
Red Hat libuserにおけるレースコンディションの脆弱性。
📍 影響範囲
libuserパッケージ内の/etc/passwdファイル処理機能。
🔥 重要度
この脆弱性が悪用されると、サービス拒否や特権の昇格が可能になるため、深刻です。
🔧 修正方法
情報なし
🛡️ 暫定回避
情報なし
🔍 検知方法
/etc/passwdファイルが予期せず変更されたか確認する。
参照URL
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory 134c704f-9b21-4f2e-91b3-4a467353bcc0
- exploit af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- web https://nvd.nist.gov/vuln/detail/CVE-2015-3246
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web https://www.exploit-db.com/exploits/44633
- web https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations
- web 134c704f-9b21-4f2e-91b3-4a467353bcc0
- web https://github.com/advisories/GHSA-f52h-j689-x786