CVE-2019-25016
Summary
| CVE | CVE-2019-25016 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-28 20:15:00 UTC |
| Updated | 2022-04-26 16:14:00 UTC |
| Description | In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue. |
Risk And Classification
Problem Types: CWE-459 | CWE-909
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Opendoas Project | Opendoas | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| redo the environment inheritance to not inherit. it was intended to m… · Duncaen/OpenDoas@01c658f · GitHub | MISC | github.com | Patch, Third Party Advisory |
| OpenDoas: Insufficient environment filtering (GLSA 202107-11) — Gentoo security | GENTOO | security.gentoo.org | |
| OpenDoas keeps current PATH variable · Issue #45 · Duncaen/OpenDoas · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| Release v6.8.1: - This release fixes one major issue that has been assigned CVE-2019-… · Duncaen/OpenDoas · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| correctly reset path for rules without specific command · Duncaen/OpenDoas@d5acd52 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.