CVE-2019-19882
Last modified
CVE-2019-19882 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and without a PAM configuration suitable for use with setuid account management tools. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and without a PAM configuration suitable for use with setuid account management tools. This combination leads to account management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that can easily be used by unprivileged local users to escalate privileges to root in multiple ways. This issue became much more relevant in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed in the upstream Makefile which is now included in the release version 4.8).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Shadow Project | Shadow | 4.8 |
References
- https://bugs.archlinux.org/task/64836Exploit, Third Party Advisory
- https://bugs.gentoo.org/702252Exploit, Third Party Advisory
- https://github.com/shadow-maint/shadow/commit/edf7547ad5aa650be868cf2dac58944773c12d75Patch, Third Party Advisory
- https://github.com/shadow-maint/shadow/pull/199Patch, Third Party Advisory
- https://github.com/void-linux/void-packages/pull/17580Patch, Third Party Advisory
- https://bugs.archlinux.org/task/64836Exploit, Third Party Advisory
- https://bugs.gentoo.org/702252Exploit, Third Party Advisory
- https://github.com/shadow-maint/shadow/commit/edf7547ad5aa650be868cf2dac58944773c12d75Patch, Third Party Advisory
- https://github.com/shadow-maint/shadow/pull/199Patch, Third Party Advisory
- https://github.com/void-linux/void-packages/pull/17580Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19882?
How severe is CVE-2019-19882?
How do I fix CVE-2019-19882?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19876An issue was discovered in B&R Industrial Automation APROL b…9.8
- CVE-2019-19877An issue was discovered in B&R Industrial Automation APROL b…5.3
- CVE-2019-19878An issue was discovered in B&R Industrial Automation APROL b…7.5
- CVE-2019-19879HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation …7.5
- CVE-2019-1988In sample6 of SkSwizzler.cpp, there is a possible out of bou…
- CVE-2019-19880exprListAppendList in window.c in SQLite 3.30.1 allows attac…7.5
- CVE-2019-19885In Bender COMTRAXX, user authorization is validated for most…9.1
- CVE-2019-19886Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker…7.5
- CVE-2019-19887bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a N…6.5
- CVE-2019-19888jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a div…6.5
- CVE-2019-19889An issue was discovered on Humax Wireless Voice Gateway HGB1…7.5
- CVE-2019-1989In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, th…
Are you affected by CVE-2019-19882?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
