Permissions, Privileges, and Access Controls - CVE-2019-10143
Published: May 24, 2019 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
** DISPUTED ** It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."
Affected software
freeradius (Alpine package)
freeradius
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Fedora
How to mitigate CVE-2019-10143
freeradius (Alpine package) - addressed in versions 3.0.15-r5, 3.0.17-r4
freeradius - addressed in versions 3.0.19-3.fc28, 3.0.19-3.fc29, 3.0.19-3.fc30
External References
- http://packetstormsecurity.com/files/155361/FreeRadius-3.0.19-Logrotate-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2019/Nov/14
- https://access.redhat.com/errata/RHSA-2019:3353
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10143
- https://freeradius.org/security/
- https://github.com/FreeRADIUS/freeradius-server/pull/2666
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A6VKBZAZKJP5QKXDXRKCM2ZPZND3TFAX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TKODLHHUOVAYENTBP4D3N25ST3Q6LJBP/