It was discovered freeradius up to and including version 3.0.19...
Vulnerability Description
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10143
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TKODLHHUOVAYENTBP4D3N25ST3Q6LJBP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6VKBZAZKJP5QKXDXRKCM2ZPZND3TFAX/
- https://access.redhat.com/errata/RHSA-2019:3353
- http://seclists.org/fulldisclosure/2019/Nov/14
- https://freeradius.org/security/
- http://packetstormsecurity.com/files/155361/FreeRadius-3.0.19-Logrotate-Privilege-Escalation.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10143
- https://github.com/FreeRADIUS/freeradius-server/pull/2666
More from freeradius
View All →Affected Vendor
freeradius
View all reports →