CVE-2019-12209
Last modified
CVE-2019-12209 is a vulnerability of currently unknown severity. Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.. EPSS estimates a 2.89% chance of exploitation in the next 30 days.
Description
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yubico | Pam-U2f | 1.0.7 |
References
- http://www.openwall.com/lists/oss-security/2019/06/05/1Exploit, Mailing List, Third Party Advisory
- https://developers.yubico.com/pam-u2f/Release_Notes.htmlRelease Notes, Vendor Advisory
- https://github.com/Yubico/pam-u2f/commit/7db3386fcdb454e33a3ea30dcfb8e8960d4c3aa3Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/05/1Exploit, Mailing List, Third Party Advisory
- https://developers.yubico.com/pam-u2f/Release_Notes.htmlRelease Notes, Vendor Advisory
- https://github.com/Yubico/pam-u2f/commit/7db3386fcdb454e33a3ea30dcfb8e8960d4c3aa3Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12209?
How severe is CVE-2019-12209?
How do I fix CVE-2019-12209?
Are you affected by CVE-2019-12209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
