Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12210

Опубликовано: 04 июн. 2019
Источник: debian
EPSS Низкий

Описание

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pam-u2ffixed1.0.8-1package
pam-u2ffixed1.0.7-1+deb10u1busterpackage
pam-u2fno-dsastretchpackage

Примечания

  • https://github.com/Yubico/pam-u2f/commit/18b1914e32b74ff52000f10e97067e841e5fff62

  • https://www.openwall.com/lists/oss-security/2019/06/05/1

EPSS

Процентиль: 62%
0.00423
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
nvd
больше 6 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
github
больше 3 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
fstec
больше 6 лет назад

Уязвимость PAM-модуля Yubico pam-u2f, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

suse-cvrf
больше 6 лет назад

Security update for libu2f-host, pam_u2f

EPSS

Процентиль: 62%
0.00423
Низкий