Vendorslibuser Projectlibuserall versions
Vulnerabilities

libuser Project libuser

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2015-3246
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Published 2015-08-11 · Analyzed
7.2KEV2 PoCEPSS 0.088
CVE-2012-5630
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
Published 2019-11-25 · Modified
6.3EPSS 0.003
CVE-2012-5644
libuser has information disclosure when moving user's home directory
Published 2019-11-25 · Analyzed
5.5EPSS 0.004