Credentials management in libosinfo - CVE-2019-13313

 

Credentials management in libosinfo - CVE-2019-13313

Published: July 5, 2019 / Updated: August 3, 2020


Vulnerability identifier: #VU33176
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13313
CWE-ID: CWE-255
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.


Affected software

libosinfo
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Fedora
libosinfo (Alpine package)
libosinfo (Red Hat package)
mingw-libosinfo
libosinfo-debugsource
libosinfo-debuginfo
libosinfo-devel
typelib-1_0-Libosinfo-1_0
libosinfo-1_0-0
libosinfo
libosinfo-1_0-0-debuginfo
libosinfo-lang

How to mitigate CVE-2019-13313

Install update from vendor's website.

libosinfo - update to 1.7.0
libosinfo (Alpine package) - update to 1.5.0-r1
libosinfo (Red Hat package) - update to 1.1.0-5.el7
mingw-libosinfo - addressed in versions 1.2.0-2.fc29, 1.4.0-3.fc30
libosinfo-debugsource - update to 1.2.0-3.3.2
libosinfo-debuginfo - update to 1.2.0-3.3.2
libosinfo-devel - update to 1.2.0-3.3.2
typelib-1_0-Libosinfo-1_0 - update to 1.2.0-3.3.2
libosinfo-1_0-0 - update to 1.2.0-3.3.2
libosinfo - update to 1.2.0-3.3.2
libosinfo-1_0-0-debuginfo - update to 1.2.0-3.3.2
libosinfo-lang - update to 1.2.0-3.3.2
libosinfo - addressed in versions 1.2.0-8.fc29, 1.4.0-4.fc30

External References

Related Security Bulletins