Permissions, Privileges, and Access Controls - CVE-2019-10143

 

Permissions, Privileges, and Access Controls - CVE-2019-10143

Published: May 24, 2019 / Updated: August 4, 2020


Vulnerability identifier: #VU33417
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10143
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

** DISPUTED ** It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."


Affected software

freeradius (Red Hat package)
freeradius (Alpine package)
freeradius
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Fedora

How to mitigate CVE-2019-10143

Install update from vendor's website.

freeradius (Red Hat package) - update to 3.0.13-15.el7
freeradius (Alpine package) - addressed in versions 3.0.15-r5, 3.0.17-r4
freeradius - addressed in versions 3.0.19-3.fc28, 3.0.19-3.fc29, 3.0.19-3.fc30

External References

Related Security Bulletins