#VU23425 Resource management error in OpenBSD - CVE-2019-19522
Published: December 5, 2019 / Updated: November 21, 2020
OpenBSD
OpenBSD
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an error in authentication process, where S/Key or YubiKey authentication is enabled. A local user can gain root privileges by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.