[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-12209 -- libpam-u2f

ID: oval:org.secpod.oval:def:1902055Date: (C)2019-06-20   (M)2023-12-20
Class: VULNERABILITYFamily: unix




Yubico libpam-u2f 1.0.7 attempts parsing of the configured authfile as root , and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.

Platform:
Ubuntu 16.04
Ubuntu 18.10
Ubuntu 18.04
Ubuntu 19.04
Product:
libpam-u2f
Reference:
CVE-2019-12209
CVE    1
CVE-2019-12209
CPE    5
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/a:yubico:libpam-u2f
cpe:/o:ubuntu:ubuntu_linux:18.10
...

© SecPod Technologies