Vulnerability Description
In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yubico | Pam-U2F | 1.0.7 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html
- http://www.openwall.com/lists/oss-security/2019/06/05/1ExploitMailing ListThird Party Advisory
- https://developers.yubico.com/pam-u2f/Release_Notes.htmlRelease NotesVendor Advisory
- https://github.com/Yubico/pam-u2f/commit/18b1914e32b74ff52000f10e97067e841e5fff6PatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html
- http://www.openwall.com/lists/oss-security/2019/06/05/1ExploitMailing ListThird Party Advisory
- https://developers.yubico.com/pam-u2f/Release_Notes.htmlRelease NotesVendor Advisory
- https://github.com/Yubico/pam-u2f/commit/18b1914e32b74ff52000f10e97067e841e5fff6PatchThird Party Advisory
FAQ
What is CVE-2019-12210?
CVE-2019-12210 is a vulnerability with a CVSS score of 8.1 (HIGH). In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descri...
How severe is CVE-2019-12210?
CVE-2019-12210 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12210?
Check the references section above for vendor advisories and patch information. Affected products include: Yubico Pam-U2F.