Rapid7 Vulnerability & Exploit Database

SUSE: CVE-2019-12210: SUSE Linux Security Advisory

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

SUSE: CVE-2019-12210: SUSE Linux Security Advisory

Severity
6
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
06/04/2019
Created
07/06/2019
Added
07/05/2019
Modified
10/22/2021

Description

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

Solution(s)

  • suse-upgrade-libu2f-host-devel
  • suse-upgrade-libu2f-host-doc
  • suse-upgrade-libu2f-host0
  • suse-upgrade-pam_u2f
  • suse-upgrade-u2f-host

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;