Vulnerability CVE-2019-3842: Information
Description
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".
Severity: HIGH (7.0) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
systemd | sisyphus | 242-alt1 | 255.6-alt2 | ALT-PU-2019-1690-1 | 227234 | Fixed |
systemd | p10 | 242-alt1 | 249.17-alt2 | ALT-PU-2019-1690-1 | 227234 | Fixed |
systemd | p9 | 242-alt1 | 247.13-alt1 | ALT-PU-2019-1690-1 | 227234 | Fixed |
systemd | p8 | 239-alt5 | 239-alt6 | ALT-PU-2020-1403-1 | 246796 | Fixed |
systemd | c10f1 | 242-alt1 | 249.17-alt2 | ALT-PU-2019-1690-1 | 227234 | Fixed |
systemd | c9f2 | 242-alt1 | 246.14-alt1 | ALT-PU-2019-1690-1 | 227234 | Fixed |
systemd | p11 | 242-alt1 | 255.6-alt2 | ALT-PU-2019-1690-1 | 227234 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842 |
|
46743 |
|
http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html |
|
[debian-lts-announce] 20190424 [SECURITY] [DLA 1762-1] systemd security update |
|
openSUSE-SU-2019:1450 |
|
FEDORA-2019-3fa5db9e19 | |
[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 | |
[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |