CVE-2005-3503 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)
Patch early
A public exploit exists.
Description
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 2.84% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-11-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| pwdutils | pwdutils |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux chfn (SuSE 9.3/10) - Local Privilege Escalation | 2005-11-08 |
References
- http://secunia.com/advisories/17469
- http://www.osvdb.org/20525
- http://www.securityfocus.com/archive/1/415725/30/0/threaded
- http://www.securityfocus.com/bid/15314
- http://secunia.com/advisories/17469
- http://www.osvdb.org/20525
- http://www.securityfocus.com/archive/1/415725/30/0/threaded
- http://www.securityfocus.com/bid/15314
→ the Explorer · watch your stack · NVD