VDB

CVE-2019-12210

CVE-2019-12210 REJECTED CVSS 8.100000381469727 HIGH

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

EPSS 2.06% · 80.6th percentile

Risk Scores

CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
2.06%
80.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSpam-u2f0, 1.0.4-2
Ubuntu:Pro:16.04:LTSpam-u2f0, 1.0.2-1, 1.0.3-1

Timeline

  • Jun 4, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
  • Sep 8, 2022 EPSS Score
  • Nov 10, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›