PT-2019-2641 · Yubico+1 · Pam-U2F+1

Matthias Gerstner

·

Publicado

2019-06-04

·

Atualizado

2024-06-15

·

CVE-2019-12210

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Yubico pam-u2f version 1.0.7
Description The issue is related to the handling of a custom debug log file when the debug option is enabled. Specifically, the file descriptor for this log file is not properly closed when a new process is spawned, allowing the child process to inherit and access the file descriptor. This can lead to sensitive information leakage and potentially allow an attacker to fill the disk or plant misinformation by writing to the file. The vulnerability is associated with a lack of protection for service data, which can be exploited by a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations For Yubico pam-u2f version 1.0.7, consider disabling the debug option or restricting access to the custom debug log file to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the debug file option to prevent potential information leakage and misuse.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02527
CVE-2019-12210
OPENSUSE-SU-2019:1708-1
OPENSUSE-SU-2019:1725-1
OPENSUSE-SU-2019_1708-1
OPENSUSE-SU-2019_1725-1
OPENSUSE-SU-2024:11145-1
SUSE-SU-2019:1749-1
SUSE-SU-2019:1750-1

Produtos afetados

Suse
Pam-U2F