CVE-2019-3842
published 2019-04-09CVE-2019-3842: In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible…
high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EXPLOIT
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | systemd | < systemd 241-3 (bookworm) | systemd 241-3 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-34_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| systemd_project | systemd | <= 241 | — |
| systemd_project | systemd | — | — |
| systemd_project | systemd | >= 0 < 241-3 | 241-3 |
| systemd_project | systemd | >= 0 < 241-3 | 241-3 |
| systemd_project | systemd | >= 0 < 241-3 | 241-3 |
| systemd_project | systemd | >= 0 < 241-3 | 241-3 |
| the_systemd_project | systemd | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH