Permissions, Privileges, and Access Controls - CVE-2019-3842

 

Permissions, Privileges, and Access Controls - CVE-2019-3842

Published: April 8, 2019


Vulnerability identifier: #VU18153
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3842
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to pam_systemd creates a user session using environmental parameters. A local user can spoof an active session and gain additional PolicyKit privileges.


Affected software

Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Fedora
Opensuse
systemd (Ubuntu package)
systemd (Debian package)
systemd (Red Hat package)
systemd
systemd-container
systemd-devel
systemd-journal-remote
systemd-libs
systemd-pam
systemd-tests
systemd-udev
Web Terminal
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2019-3842

Install updates from vendor's website.

Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
systemd (Ubuntu package) - addressed in versions 204-5ubuntu20.31, 229-4ubuntu21.21, 237-3ubuntu10.19, 239-7ubuntu10.12
systemd (Debian package) - update to 232-25+deb9u11
systemd (Red Hat package) - addressed in versions 239-31.el8_2.7, 239-45.el8
Web Terminal - update to 1.3
OpenShift Virtualization - update to 4.8.0
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
systemd - update to 239-31.0.1
systemd-container - update to 239-31.0.1
systemd-devel - update to 239-31.0.1
systemd-journal-remote - update to 239-31.0.1
systemd-libs - update to 239-31.0.1
systemd-pam - update to 239-31.0.1
systemd-tests - update to 239-31.0.1
systemd-udev - update to 239-31.0.1
systemd - update to 241-5.git3d835d0.fc30

External References

Related Security Bulletins