Bug 1787080 (CVE-2019-18898) - CVE-2019-18898 trousers: local privilege escalation from tss to root
Summary: CVE-2019-18898 trousers: local privilege escalation from tss to root
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2019-18898
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1787081
TreeView+ depends on / blocked
 
Reported: 2019-12-30 20:39 UTC by Guilherme de Almeida Suckevicz
Modified: 2021-02-16 20:49 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-12-30 21:08:59 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2019-12-30 20:39:21 UTC
Fixed a local symlink attack where a rogue tss user could have gain ownership of arbitrary files in the system during installation/update of the trousers package.

Reference:
https://www.tenable.com/plugins/nessus/132338

Comment 1 Marco Benatto 2019-12-30 21:07:11 UTC
Statement:

The trousers versions as shipped as Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue. The flaw resides on the post transaction scriptlet from the RPM package. This scriptlet doesn't exists on Red Hat Enterprise Linux RPM spec file.

Comment 2 Marco Benatto 2019-12-30 21:08:36 UTC
Closing this flaw as NOTABUG as Red Hat's RPM packages for trousers doesn't execute the rpmsave data backup on post transaction scriptlet.


Note You need to log in before you can comment on or make changes to this bug.