HIGH
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root
Published Jun 4, 2019
7.5
HIGHCVSS 3.0
EPSS 2.89%
Description
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html vendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2019/06/05/1 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- https://developers.yubico.com/pam-u2f/Release_Notes.html x_refsource_CONFIRMRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3854 Advisory
- https://github.com/Yubico/pam-u2f/commit/7db3386fcdb454e33a3ea30dcfb8e8960d4c3aa3 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FOR4ADC356JPCHAJI5UXZORLC3VNBPS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCGU6UQLI3ZTW3UYCTMQW7VDL5M4LCWR/ vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html | vendor-advisoryx_refsource_SUSE | |
| http://www.openwall.com/lists/oss-security/2019/06/05/1 | mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory | |
| https://developers.yubico.com/pam-u2f/Release_Notes.html | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3854 | Advisory | |
| https://github.com/Yubico/pam-u2f/commit/7db3386fcdb454e33a3ea30dcfb8e8960d4c3aa3 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FOR4ADC356JPCHAJI5UXZORLC3VNBPS/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCGU6UQLI3ZTW3UYCTMQW7VDL5M4LCWR/ | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 4, 2019
Updated Aug 4, 2024
Reserved May 20, 2019
Link CVE-2019-12209
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-3854 Assigner mitre
Published Jun 4, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-3854