First published: Wed Dec 04 2019(Updated: )
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbsd Openbsd | =6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19519 is a vulnerability in OpenBSD 6.6 that allows local users to achieve any login class (often excluding root) through the su -L option due to a logic error in the main function in su/su.c.
CVE-2019-19519 has a severity score of 7.8, which is considered high.
CVE-2019-19519 affects OpenBSD 6.6.
Local users can exploit CVE-2019-19519 by using the su -L option to achieve any login class, except root, due to a logic error in the main function in su/su.c.
Yes, you can refer to the following links for more information: [1] http://packetstormsecurity.com/files/155572/Qualys-Security-Advisory-OpenBSD-Authentication-Bypass-Privilege-Escalation.html [2] http://seclists.org/fulldisclosure/2019/Dec/14 [3] http://www.openwall.com/lists/oss-security/2019/12/04/5