Incomplete blacklist vulnerability in the chfn function...
Low severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
Aug 11, 2015
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Apr 12, 2025
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.
References