systemd: Spoofing of XDG_SEAT allows for actions to be checked against "allow_active" instead of "allow_any"
Published Apr 9, 2019
7.0
HIGHCVSS 3.1
EPSS 1.21%
Description
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".
Affected products
-
- Version v242-rc4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The systemd Project | Systemd | n/a |
|
Configuration 1
- ≤ 241
- 242
- 242
- 242
Configuration 2
- 7.0
Configuration 3
- 30
Configuration 4
- 8.0
No data.
Red Hat Enterprise Linux 8
systemd-0:239-45.el8
Fixed · RHSA-2021:1611
Red Hat Enterprise Linux 8.2 Extended Update Support
systemd-0:239-31.el8_2.7
Fixed · RHSA-2021:3900
Red Hat Enterprise Linux 7
systemd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | systemd-0:239-45.el8 | Fixed | RHSA-2021:1611 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | systemd-0:239-31.el8_2.7 | Fixed | RHSA-2021:3900 |
| Red Hat Enterprise Linux 7 | systemd | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
For the attack to be successful, a new session must be created by pam_systemd. This is done only if the calling process is not already part of a session. Red Hat Enterprise Linux, in its default PAM configurations, does not let a session sneak in without systemd knowing about it, since pam_systemd is always called in every PAM config file. Unless a wrong PAM config file is in place, this vulnerability cannot be triggered on Red Hat Enterprise Linux 7 and 8.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-3842 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1668521 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STR36RJE4ZZIORMDXRERVBHMPRNRTHAC/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-3842
- https://www.cve.org/CVERecord?id=CVE-2019-3842
- https://www.exploit-db.com/exploits/46743/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.