CVE-2019-7249: Critical severity keybase vulnerability
Published Jan 31, 2019
·Updated
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.
Affected Software
1 affected component
Keybase Keybase Macos<2.12.6
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2019
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Data Sourced
via NVD·09:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-7249?
CVE-2019-7249 is a vulnerability in Keybase before version 2.12.6 on macOS.
2
How severe is CVE-2019-7249?
CVE-2019-7249 has a severity rating of 9.8 (Critical).
3
How does CVE-2019-7249 affect Keybase?
CVE-2019-7249 affects Keybase versions before 2.12.6 on macOS.
4
What is the impact of CVE-2019-7249?
CVE-2019-7249 allows one user of the system to tamper with another's installs on Keybase, without requiring root access.
5
How can I fix CVE-2019-7249?
To fix CVE-2019-7249, it is recommended to update Keybase to version 2.12.6 or later on macOS.