Back

MEDIUM

libuser: (Complete) Information disclosure when moving user's home directory

Published Nov 25, 2019

Description

libuser has information disclosure when moving user's home directory

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Red Hat mitigation

There are several restrictions to successful exploitation of this flaw: ~~~ 1. ONLY applications compiled with libuser are affected. The affected code is hit only when a move operation is conducted on user home directory. 2. The attacker needs to have a shell account on the target machine. 3. Since this is a TOCTOU attack, precise timing is required for the attack. The attacker needs to know exactly when the move directory is moved in order successfully exploit this flaw. ~~~ Any other application acting on user directories (not compiled with libuser) for example usermod/userdel are not affected by this flaw.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 25, 2019
Updated Aug 6, 2024
Reserved Oct 24, 2012
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 28, 2013