---
id: CVE-2015-3246
title: >-
  libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper
  program in the usermode package, directly modifies /etc/passwd, which allows
  local users to cause a denial of service (inconsistent file state) by causing
  an erro…
summary: >-
  libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper
  program in the usermode package, directly modifies /etc/passwd, which allows
  local users to cause a denial of service (inconsistent file state) by causing
  an erro…
severity: medium
cvss: 5.1
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-264
  - CWE-367
vendor: redhat
product: libuser
affected:
  - libuser <= 0.56.13-5
  - libuser = 0.60-1
  - libuser = 0.60-2
  - libuser = 0.60-3
  - libuser = 0.60-4
  - libuser = 0.60-5
  - libuser = 0.60-6
published: '2015-08-11'
updated: '2026-08-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2015-3246'
references:
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html
    label: secalert@redhat.com
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
    label: secalert@redhat.com
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1482.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1483.html'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/76022'
    label: secalert@redhat.com
  - url: 'http://www.securitytracker.com/id/1033040'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/articles/1537873'
    label: secalert@redhat.com
  - url: 'https://www.exploit-db.com/exploits/44633/'
    label: secalert@redhat.com
  - url: >-
      https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
    label: secalert@redhat.com
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1482.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1483.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/76022'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1033040'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/articles/1537873'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/44633/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.08799
epssPercentile: 0.95001
kev: true
kevDateAdded: '2026-08-26'
kevDueDate: '2026-09-09'
kevRansomware: false
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-26T18:47:53.340Z'
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2015-3246'
  metasploit:
    - exploit/linux/local/libuser_roothelper_priv_esc
  checkedAt: '2026-09-21T15:23:33.762Z'
---

## Overview

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

## Affected

- `libuser <= 0.56.13-5`
- `libuser = 0.60-1`
- `libuser = 0.60-2`
- `libuser = 0.60-3`
- `libuser = 0.60-4`
- `libuser = 0.60-5`
- `libuser = 0.60-6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
