CVE-2019-10143
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-250, CWE-266, CWE-362
- Affected
- freeradius/freeradius · fedoraproject/fedora · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- http://packetstormsecurity.com/files/155361/FreeRadius-3.0.19-Logrotate-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/14Exploit, Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3353Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10143Issue Tracking, Third Party Advisory
- https://freeradius.org/security/Third Party Advisory
- https://github.com/FreeRADIUS/freeradius-server/pull/2666Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6VKBZAZKJP5QKXDXRKCM2ZPZND3TFAX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TKODLHHUOVAYENTBP4D3N25ST3Q6LJBP/
- http://packetstormsecurity.com/files/155361/FreeRadius-3.0.19-Logrotate-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/14Exploit, Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3353Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10143Issue Tracking, Third Party Advisory
- https://freeradius.org/security/Third Party Advisory
- https://github.com/FreeRADIUS/freeradius-server/pull/2666Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6VKBZAZKJP5QKXDXRKCM2ZPZND3TFAX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TKODLHHUOVAYENTBP4D3N25ST3Q6LJBP/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.