Vulnerability Name:

CVE-2019-12209 (CCN-162187)

Assigned:2019-06-04
Published:2019-06-04
Updated:2020-08-24
Summary:Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-59
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2019-12209

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1708

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:1725

Source: MLIST
Type: Exploit, Mailing List, Third Party Advisory
[oss-security] 20190605 pam-u2f: CVE-2019-12210: debug_file file descriptor leak, CVE-2019-12209: symlink attack on u2f_keys leading to possible information leak

Source: CONFIRM
Type: Release Notes, Vendor Advisory
https://developers.yubico.com/pam-u2f/Release_Notes.html

Source: XF
Type: UNKNOWN
yubico-cve201912209-info-disc(162187)

Source: CCN
Type: pam-u2f GIT Repository
Drop privileges by default when opening user-related files

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/Yubico/pam-u2f/commit/7db3386fcdb454e33a3ea30dcfb8e8960d4c3aa3

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-b6d3c8b0a8

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-cd8f4b9568

Source: CCN
Type: oss-sec Mailing List, Wed, 5 Jun 2019 11:59:31 +0200
pam-u2f: CVE-2019-12210: debug_file file descriptor leak, CVE-2019-12209: symlink attack on u2f_keys leading to possible information leak

Vulnerable Configuration:Configuration 1:
  • cpe:/a:yubico:pam-u2f:1.0.7:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:yubico:pam-u2f:1.0.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201912209
    V
    CVE-2019-12209
    2023-06-22
    oval:org.opensuse.security:def:7624
    P
    libnghttp2-14-1.40.0-6.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7733
    P
    pam_u2f-1.2.0-150400.2.4 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7602
    P
    libjasper4-2.0.14-150000.3.28.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:55528
    P
    Security update for openssl-1_1 (Moderate)
    2023-04-04
    oval:org.opensuse.security:def:3475
    P
    dovecot22-2.2.31-19.17.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3139
    P
    libXfont2-2-2.0.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3487
    P
    file-5.22-10.12.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3319
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3215
    P
    libncurses5-32bit-5.9-64.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3227
    P
    libotr5-4.0.0-9.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94769
    P
    pam_u2f-1.2.0-150400.2.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1187
    P
    Security update for ImageMagick (Moderate) (in QA)
    2022-06-16
    oval:org.opensuse.security:def:258
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1340
    P
    Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP3) (Important)
    2022-05-09
    oval:org.opensuse.security:def:849
    P
    Security update for python (Moderate)
    2022-04-01
    oval:org.opensuse.security:def:113091
    P
    pam_u2f-1.1.1-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64835
    P
    Security update for systemd (Moderate)
    2022-01-11
    oval:org.opensuse.security:def:49125
    P
    Security update for sles12sp2-docker-image (Important)
    2021-12-13
    oval:org.opensuse.security:def:8877
    P
    Security update for MozillaFirefox (Important)
    2021-12-10
    oval:org.opensuse.security:def:9626
    P
    Security update for clamav (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:8675
    P
    Security update for netcdf (Important)
    2021-11-25
    oval:org.opensuse.security:def:9604
    P
    Security update for dnsmasq (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:69941
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:55254
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:106528
    P
    pam_u2f-1.1.1-1.3 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:51660
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:71422
    P
    xorg-x11-server-1.20.3-12.29 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63212
    P
    libecpg6-10.6-6.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:6964
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP1) (Important)
    2021-09-16
    oval:org.opensuse.security:def:8653
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:23665
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:8645
    P
    Security update for dovecot23 (Moderate)
    2021-08-31
    oval:org.opensuse.security:def:64748
    P
    Security update for libmspack (Moderate)
    2021-08-20
    oval:org.opensuse.security:def:6951
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:47134
    P
    python-2.7.9-24.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48258
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48200
    P
    libssh2-1-1.4.3-20.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48064
    P
    libHX28-3.18-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48318
    P
    sysstat-12.0.2-10.24.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47858
    P
    powerpc-utils-1.3.5-3.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47872
    P
    python3-requests-2.7.0-2.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:15138
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48065
    P
    libICE6-1.0.8-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47993
    P
    dosfstools-3.0.26-6.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47857
    P
    policycoreutils-2.5-10.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48079
    P
    libXi6-1.7.4-18.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47083
    P
    libtag1-1.9.1-1.218 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:1547
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:63344
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63383
    P
    virt-install-3.2.0-5.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63448
    P
    php7-embed-7.4.6-1.11 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62339
    P
    tpm2.0-tools-4.3.0-2.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72087
    P
    vim-8.0.1568-5.14.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62817
    P
    libthai0-32bit-0.1.27-1.16 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62338
    P
    tcpdump-4.9.2-3.15.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71971
    P
    libtirpc-devel-1.2.6-1.131 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63019
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62337
    P
    tboot-20170711_1.9.8-15.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101034
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62276
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72017
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62361
    P
    yast2-security-4.3.16-1.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62064
    P
    dracut-049.1+suse.187.g63c1504f-3.27.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:65297
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:6942
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-07-28
    oval:org.opensuse.security:def:6933
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 15 SP1) (Important)
    2021-07-27
    oval:org.opensuse.security:def:51920
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:51598
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:23609
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:8783
    P
    Security update for spice (Important)
    2021-06-11
    oval:org.opensuse.security:def:48765
    P
    bogofilter-1.2.4-5.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46445
    P
    java-1_7_0-openjdk-1.7.0.65-3.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12758
    P
    xorg-x11-libs-7.6-45.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48856
    P
    libid3tag0-0.15.1b-182.58 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:1978
    P
    pam-modules-12.1-3.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13663
    P
    libvorbis-doc-1.3.3-8.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12682
    P
    pam_yubico-2.26-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48393
    P
    cups-1.7.5-12.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13641
    P
    libproxy1-0.4.11-11.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48410
    P
    elfutils-0.158-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48525
    P
    libmusicbrainz4-2.1.5-27.79 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63546
    P
    libmwaw-0_3-3-0.3.13-2.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12690
    P
    perl-Tk-804.031-3.82 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48558
    P
    libtcnative-1-0-1.1.32-9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48617
    P
    rsync-3.1.0-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48918
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46380
    P
    apache2-2.4.10-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12712
    P
    rpm-32bit-4.11.2-16.16.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48772
    P
    gcc48-gij-32bit-4.8.5-30.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:100618
    P
    (Moderate)
    2021-06-04
    oval:org.opensuse.security:def:8944
    P
    Security update for avahi (Moderate)
    2021-06-04
    oval:org.opensuse.security:def:8768
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:6673
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15) (Important)
    2021-05-25
    oval:org.opensuse.security:def:6900
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP1) (Important)
    2021-05-25
    oval:org.opensuse.security:def:68182
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2) (Important)
    2021-05-25
    oval:org.opensuse.security:def:8953
    P
    Security update for lz4 (Important)
    2021-05-19
    oval:org.opensuse.security:def:56997
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:69836
    P
    Security update for stunnel (Important)
    2021-05-03
    oval:org.opensuse.security:def:45307
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:8935
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:6875
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP1) (Important)
    2021-04-07
    oval:org.opensuse.security:def:8721
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:49190
    P
    Security update for compat-openssl098 (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:8902
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:38434
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:6719
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15) (Important)
    2021-02-10
    oval:org.opensuse.security:def:68082
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-02-10
    oval:org.opensuse.security:def:8802
    P
    Security update for nodejs8 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:23600
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:8966
    P
    Security update for wavpack (Moderate)
    2021-01-21
    oval:org.opensuse.security:def:66493
    P
    Security update for tomcat (Moderate)
    2021-01-07
    oval:org.opensuse.security:def:23975
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:23905
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:56923
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:74272
    P
    Security update for openexr (Moderate)
    2020-12-24
    oval:org.opensuse.security:def:54697
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:37535
    P
    Security update for openssl1 (Important)
    2020-12-09
    oval:org.opensuse.security:def:51858
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-09
    oval:org.opensuse.security:def:6643
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15) (Important)
    2020-12-07
    oval:org.opensuse.security:def:61867
    P
    libpoppler-cpp0-0.79.0-1.89 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62538
    P
    libXcursor1-32bit-1.1.15-1.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12981
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107284
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2528
    P
    gimp-2.10.12-1.100 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49014
    P
    libiso9660-8-0.90-6.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49022
    P
    libntfs-3g84-2013.1.13-5.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12939
    P
    libICE6-1.0.8-12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:46351
    P
    facter-2.0.2-1.6 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2490
    P
    gstreamer-plugins-ugly-1.12.5-1.35 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48979
    P
    cyrus-sasl-digestmd5-32bit-2.1.26-8.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63586
    P
    libntfs-3g87-2016.2.22-3.3.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12805
    P
    libpacemaker3-1.1.21+20190809.bf34b44fa-1.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2537
    P
    libical-glib-devel-3.0.6-2.70 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61938
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13132
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13003
    P
    libjansson4-2.12-3.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62537
    P
    libSoundTouch0-1.8.0-3.11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49003
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2496
    P
    libmwaw-0_3-3-0.3.14-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:93905
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2486
    P
    gimp-2.8.22-3.42 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48983
    P
    evolution-3.22.6-19.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71679
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63641
    P
    openconnect-7.08-6.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61868
    P
    libpq5-12.2-6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12820
    P
    apache-commons-beanutils-1.9.2-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2185
    P
    libfreebl3-hmac-3.47.1-3.37.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62671
    P
    libgypsy-devel-0.9-2.30 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2508
    P
    libwpd-0_10-10-0.10.2-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63157
    P
    libcacard-devel-2.5.3-1.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12990
    P
    libgme0-0.6.0-5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61891
    P
    libtasn1-4.13-4.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12839
    P
    bluez-5.13-5.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62889
    P
    bsdtar-3.3.2-3.8.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2522
    P
    colord-gtk-lang-0.1.26-1.48 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71535
    P
    libXi-devel-1.7.9-3.2.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49004
    P
    libIlmImf-Imf_2_1-21-32bit-2.1.0-6.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12914
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116842
    P
    pam_u2f-1.0.8-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2827
    P
    Security update for libvpx (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2782
    P
    Security update for vim (Important)
    2020-12-02
    oval:org.opensuse.security:def:2837
    P
    Security update for fwupd (Important)
    2020-12-02
    oval:org.opensuse.security:def:49290
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:2788
    P
    Security update for wireshark (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2575
    P
    Security update for java-11-openjdk (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2750
    P
    Security update for ImageMagick (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2561
    P
    Security update for MozillaThunderbird and mozilla-nspr (Important)
    2020-12-02
    oval:org.opensuse.security:def:2797
    P
    Security update for openexr (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2835
    P
    Security update for file-roller (Low)
    2020-12-02
    oval:org.opensuse.security:def:2756
    P
    Security update for netpbm (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2746
    P
    Security update for libqt5-qtimageformats (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2567
    P
    Security update for wireshark (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2821
    P
    Security update for webkit2gtk3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:2768
    P
    Security update for libvpx (Important)
    2020-12-02
    oval:org.opensuse.security:def:2577
    P
    Security update for wireshark (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:54286
    P
    libmspack0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45728
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50343
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24258
    P
    Security update for ipmitool (Important)
    2020-12-01
    oval:org.opensuse.security:def:54123
    P
    strongswan on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50218
    P
    argyllcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36907
    P
    libgssglue1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49598
    P
    rtkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68631
    P
    Security update for libarchive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6651
    P
    lftp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68734
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45295
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49760
    P
    perl-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63710
    P
    Security update for openssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37375
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6800
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50582
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54524
    P
    libXrandr2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45812
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64052
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49264
    P
    libxml2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24118
    P
    Security update for perl (Important)
    2020-12-01
    oval:org.opensuse.security:def:37643
    P
    perl-LWP-Protocol-https on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49236
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66585
    P
    pam_u2f on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36991
    P
    perl-Cyrus-IMAP on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49755
    P
    perl-DNS-LDNS on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55566
    P
    Recommended update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36895
    P
    libcgroup-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55362
    P
    python-imaging on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50478
    P
    Security update for gcc7 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49858
    P
    perl-Net-Libproxy on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63844
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:24246
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49085
    P
    ecryptfs-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:23783
    P
    Security update for libxslt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50153
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49149
    P
    libXrandr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49221
    P
    libprocps7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45946
    P
    Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP3) (Important)
    2020-12-01
    oval:org.opensuse.security:def:49063
    P
    c-ares-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49282
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24167
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63691
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73276
    P
    pam_u2f on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37127
    P
    glib2-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49993
    P
    apache2-mod_wsgi-python3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55647
    P
    Security update for ldb, samba, talloc, tdb, tevent (Important)
    2020-12-01
    oval:org.opensuse.security:def:46292
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:64206
    P
    alsa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50361
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:63726
    P
    Security update for libu2f-host (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54124
    P
    sudo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45420
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50015
    P
    libspice-server-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63950
    P
    Security update for virglrenderer (Important)
    2020-12-01
    oval:org.opensuse.security:def:37710
    P
    xlockmore on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50415
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45294
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:23856
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:37594
    P
    libtcnative-1-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73158
    P
    libhogweed4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24966
    P
    Security update for libu2f-host (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49354
    P
    wicked on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49292
    P
    patch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54803
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46153
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:50413
    P
    Security update for python-paramiko (Important)
    2020-12-01
    oval:org.opensuse.security:def:24296
    P
    Security update for openssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49409
    P
    gnome-settings-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50249
    P
    libwmf-0_2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38392
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49263
    P
    libxkbcommon-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37228
    P
    libmysqlclient18 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50083
    P
    memcached on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24934
    P
    Security update for systemd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6766
    P
    libtag1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74146
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:54146
    P
    xorg-x11-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45604
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 12 SP3) (Important)
    2020-12-01
    oval:org.opensuse.security:def:50253
    P
    strongswan-nm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37754
    P
    cpio on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50568
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:36896
    P
    libdcerpc-binding0-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49500
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50622
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54969
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:46233
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64094
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:49614
    P
    bluez-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37682
    P
    stunnel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50322
    P
    Security update for zziplib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37285
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6781
    P
    libxcb-dri2-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55454
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50509
    P
    Security update for gcc9 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65387
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:109896
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2019-07-19
    oval:org.opensuse.security:def:97718
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:90753
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:79631
    P
    Security update for libu2f-host (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:124866
    P
    Security update for libu2f-host (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:103816
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:126280
    P
    Security update for libu2f-host (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:88704
    P
    Security update for libu2f-host (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:104408
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2019-07-04
    oval:org.opensuse.security:def:90161
    P
    Security update for libu2f-host, pam_u2f (Moderate)
    2019-07-04
    oval:com.ubuntu.cosmic:def:2019122090000000
    V
    CVE-2019-12209 on Ubuntu 18.10 (cosmic) - medium.
    2019-06-04
    oval:com.ubuntu.disco:def:2019122090000000
    V
    CVE-2019-12209 on Ubuntu 19.04 (disco) - medium.
    2019-06-04
    oval:com.ubuntu.bionic:def:2019122090000000
    V
    CVE-2019-12209 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-06-04
    oval:com.ubuntu.xenial:def:2019122090000000
    V
    CVE-2019-12209 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-06-04
    BACK
    yubico pam-u2f 1.0.7
    yubico pam-u2f 1.0.7