Important CentOS libuser Security Update

Metadata

high
7.2
libuser-0.60-7.el7_1.i686.rpm, libuser-0.60-7.el7_1.src.rpm, libuser-0.60-7.el7_1.x86_64.rpm, libuser-devel-0.60-7.el7_1.i686.rpm, libuser-devel-0.60-7.el7_1.x86_64.rpm, libuser-python-0.60-7.el7_1.x86_64.rpm
CVE-2015-3245, CVE-2015-3246
rhn.redhat.com, lists.centos.org
2015-07-24
2017-07-27 19:09
ALAS-2015-572
Important CentOS libuser Security Update
CVE-2015-3245 libuser
CVE-2015-3246 libuser
CVE-2015-3246
CVE-2015-3245
2017-04-01 19:09
2017-01-05 20:13

Description


Updated libuser packages that fix two security issues are now available for
Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.

The libuser library implements a standardized interface for manipulating
and administering user and group accounts. Sample applications that are
modeled after applications from the shadow password suite (shadow-utils)
are included in these packages.

Two flaws were found in the way the libuser library handled the /etc/passwd
file. A local attacker could use an application compiled against libuser
(for example, userhelper) to manipulate the /etc/passwd file, which could
result in a denial of service or possibly allow the attacker to escalate
their privileges to root. (CVE-2015-3245, CVE-2015-3246)

Red Hat would like to thank Qualys for reporting these issues.

All libuser users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
7 libuser libuser-0.60-7.el7_1.i686.rpm
libuser libuser-0.60-7.el7_1.src.rpm
libuser libuser-0.60-7.el7_1.x86_64.rpm
libuser-devel libuser-devel-0.60-7.el7_1.i686.rpm
libuser-devel libuser-devel-0.60-7.el7_1.x86_64.rpm
libuser-python libuser-python-0.60-7.el7_1.x86_64.rpm