VDB
CVE-2019-12210
CVE-2019-12210
REJECTED
In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.
EPSS 0.40% · 61.1th percentile
Risk Scores
EPSS Score
0.40%
61.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | pam-u2f | 0, 1.0.4-2 |
| Ubuntu:Pro:16.04:LTS | pam-u2f | 0, 1.0.2-1, 1.0.3-1 |
Exploit Intelligence
Timeline
- Jun 4, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-12210 third-party-advisory
- https://www.openwall.com/lists/oss-security/2019/06/05/1 third-party-advisory
- https://developers.yubico.com/pam-u2f/Release_Notes.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-12210 third-party-advisory