Information disclosure in Debian Linux - CVE-2019-13033

 

Information disclosure in Debian Linux - CVE-2019-13033

Published: June 18, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34247
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13033
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be possible to upload the data of additional scans.


Affected software

Debian Linux
Amazon Linux AMI
Fedora
lynis

How to mitigate CVE-2019-13033

Install update from vendor's website.

lynis - addressed in versions 3.0.0-1.el7, 3.0.0-1.el8, 3.0.0-1.fc31, 3.0.0-1.fc32

External References

Related Security Bulletins