HIGH
libqb: Insecure treatment of IPC (temporary) files
Published Jun 7, 2019
7.1
HIGHCVSS 3.0
EPSS 0.66%
Description
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
Affected products
No data.
- < 1.0.5
No data.
Red Hat Enterprise Linux 7
libqb-0:1.0.1-9.el7
Fixed · RHSA-2020:1189
Red Hat Enterprise Linux 8
libqb-0:1.0.3-10.el8
Fixed · RHSA-2019:3610
Red Hat Enterprise Linux 6
libqb
Out of support scope
Red Hat Storage 3
libqb
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libqb-0:1.0.1-9.el7 | Fixed | RHSA-2020:1189 |
| Red Hat Enterprise Linux 8 | libqb-0:1.0.3-10.el8 | Fixed | RHSA-2019:3610 |
| Red Hat Enterprise Linux 6 | libqb | Out of support scope | n/a |
| Red Hat Storage 3 | libqb | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00017.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00027.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00031.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/108691 vdb-entryx_refsource_BIDThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3610 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-12779 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1695948 x_refsource_MISCExploitPatchThird Party AdvisoryVDB EntryIssue Tracking
- https://github.com/ClusterLabs/libqb/issues/338 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://github.com/ClusterLabs/libqb/releases/tag/v1.0.4 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/ClusterLabs/libqb/releases/tag/v1.0.5 x_refsource_MISCRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-12779
- https://security.gentoo.org/glsa/202107-03 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2019-12779
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 7, 2019
Updated Aug 4, 2024
Reserved Jun 7, 2019
Link CVE-2019-12779
CISA Vulnrichment
Updated n/a