Permissions, Privileges, and Access Controls in Sudo - CVE-2019-19234

 

Permissions, Privileges, and Access Controls in Sudo - CVE-2019-19234

Published: December 20, 2019 / Updated: January 30, 2020


Vulnerability identifier: #VU23782
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19234
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to impersonate other users on the system.

The vulnerability exists due to incorrect handling of the blocked users (e.g., by using the ! character in the shadow file instead of a password hash) in sudo. A local user with access to a Runas ALL sudoer account can impersonate blocked users.


Affected software

Sudo
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Integrated Analytics System
Oracle Solaris
Fedora
sudo

How to mitigate CVE-2019-19234

Install update from vendor's website.

Sudo - update to 1.8.30
IBM Integrated Analytics System - update to 1.0.31.0
sudo - addressed in versions 1.9.0-0.1.b1.fc31, 1.9.0-0.1.b1.fc32

External References

Related Security Bulletins