SB2019050930 - Fedora 30 update for freeradius



SB2019050930 - Fedora 30 update for freeradius

Published: May 9, 2019 Updated: April 25, 2025

Security Bulletin ID SB2019050930
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-10143)

The vulnerability allows a local authenticated user to execute arbitrary code.

** DISPUTED ** It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."


Remediation

Install update from vendor's website.