PT-2019-2641 · Yubico+1 · Pam-U2F+1

Matthias Gerstner

·

Published

2019-06-04

·

Updated

2024-06-15

·

CVE-2019-12210

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Yubico pam-u2f version 1.0.7
Description The issue is related to the handling of a custom debug log file when the debug option is enabled. Specifically, the file descriptor for this log file is not properly closed when a new process is spawned, allowing the child process to inherit and access the file descriptor. This can lead to sensitive information leakage and potentially allow an attacker to fill the disk or plant misinformation by writing to the file. The vulnerability is associated with a lack of protection for service data, which can be exploited by a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations For Yubico pam-u2f version 1.0.7, consider disabling the debug option or restricting access to the custom debug log file to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the debug file option to prevent potential information leakage and misuse.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02527
CVE-2019-12210
OPENSUSE-SU-2019:1708-1
OPENSUSE-SU-2019:1725-1
OPENSUSE-SU-2019_1708-1
OPENSUSE-SU-2019_1725-1
OPENSUSE-SU-2024:11145-1
SUSE-SU-2019:1749-1
SUSE-SU-2019:1750-1

Affected Products

Suse
Pam-U2F