Логотип exploitDog
bind:CVE-2019-12210
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12210

Количество 9

Количество 9

ubuntu логотип

CVE-2019-12210

больше 6 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2019-12210

больше 6 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2019-12210

больше 6 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pxf2-5pmm-5r8f

больше 3 лет назад

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2019-02527

больше 6 лет назад

Уязвимость PAM-модуля Yubico pam-u2f, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1725-1

больше 6 лет назад

Security update for libu2f-host, pam_u2f

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1708-1

больше 6 лет назад

Security update for libu2f-host, pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1750-1

больше 6 лет назад

Security update for libu2f-host, pam_u2f

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1749-1

больше 6 лет назад

Security update for libu2f-host

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-12210

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12210

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12210

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug ...

CVSS3: 8.1
0%
Низкий
больше 6 лет назад
github логотип
GHSA-pxf2-5pmm-5r8f

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-02527

Уязвимость PAM-модуля Yubico pam-u2f, связанная с отсутствием защиты служебных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 8.1
0%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1725-1

Security update for libu2f-host, pam_u2f

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1708-1

Security update for libu2f-host, pam_u2f

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1750-1

Security update for libu2f-host, pam_u2f

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1749-1

Security update for libu2f-host

больше 6 лет назад

Уязвимостей на страницу