← Back
CVE-2015-3246
CISA KEV
medium
CVSS 5.1
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
Summary
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
AI summary openai / gpt-4o
Red Hat libuserにレースコンディションの脆弱性があり、認証されたローカルユーザーが/etc/passwdファイルを破損させ、サービス拒否や特権の昇格を引き起こす可能性があります。この脆弱性はローカル環境で悪用される可能性があり、特に高いリスクを持っています。
❓ What is the problem
Red Hat libuserにおけるレースコンディションの脆弱性。
📍 Affected scope
libuserパッケージ内の/etc/passwdファイル処理機能。
🔥 Severity
この脆弱性が悪用されると、サービス拒否や特権の昇格が可能になるため、深刻です。
🔧 How to fix
情報なし
🛡️ Workaround
情報なし
🔍 Detection
/etc/passwdファイルが予期せず変更されたか確認する。
References
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory 134c704f-9b21-4f2e-91b3-4a467353bcc0
- exploit af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- web https://nvd.nist.gov/vuln/detail/CVE-2015-3246
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web https://www.exploit-db.com/exploits/44633
- web https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations
- web 134c704f-9b21-4f2e-91b3-4a467353bcc0
- web https://github.com/advisories/GHSA-f52h-j689-x786