Vulnerability CVE-2005-3503


Published: 2005-11-05   Modified: 2012-02-12

Description:
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

Type:

CWE-Other

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Pwdutils -> Pwdutils 

 References:
http://www.securityfocus.com/archive/1/415725/30/0/threaded
http://www.securityfocus.com/bid/15314

Copyright 2024, cxsecurity.com

 

Back to Top