Vulnerability Name:

CVE-2019-13313 (CCN-163457)

Assigned:2019-07-05
Published:2019-07-05
Updated:2023-02-28
Summary:libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
2.8 Low (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
2.5 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2019-13313

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
libosinfo-cve201913313-info-disc(163457)

Source: cve@mitre.org
Type: Release Notes, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Release Notes, Third Party Advisory
cve@mitre.org

Source: CCN
Type: libosinfo Web site
libosinfo The Operating System information database

Source: cve@mitre.org
Type: Release Notes, Vendor Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: oss-sec Mailing List, Mon, 8 Jul 2019 16:59:35 +0530 (IST)
CVE-2019-13313, CVE-2019-13314: password disclosure via command line arguments

Source: cve@mitre.org
Type: Mailing List, Patch, Third Party Advisory
cve@mitre.org

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201913313
    V
    CVE-2019-13313
    2023-06-22
    oval:org.opensuse.security:def:7634
    P
    libosinfo-1.10.0-150500.1.3 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:768
    P
    Security update for wireshark (Moderate)
    2022-09-19
    oval:org.opensuse.security:def:42415
    P
    Security update for systemd-presets-common-SUSE (Moderate) (in QA)
    2022-07-13
    oval:org.opensuse.security:def:93824
    P
    (Important)
    2022-07-06
    oval:org.opensuse.security:def:3049
    P
    davfs2-1.5.2-2.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3493
    P
    g3utils-1.1.36-58.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94679
    P
    libosinfo-1.7.1-150400.8.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95123
    P
    libosinfo-devel-1.7.1-150400.8.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:173
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:42289
    P
    Security update for libxml2 (Important)
    2022-05-19
    oval:org.opensuse.security:def:42386
    P
    Security update for ucode-intel (Moderate)
    2022-05-18
    oval:org.opensuse.security:def:42341
    P
    Security update for polkit (Moderate)
    2022-02-18
    oval:org.opensuse.security:def:112747
    P
    libosinfo-1.9.0-1.5 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:56109
    P
    Security update for chrony (Moderate)
    2021-12-22
    oval:org.opensuse.security:def:69755
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:55969
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:42225
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:106219
    P
    libosinfo-1.9.0-1.5 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:1633
    P
    Security update for linuxptp (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:20981
    P
    Security update for nodejs14 (Important)
    2021-09-22
    oval:org.opensuse.security:def:55947
    P
    Security update for Mesa (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:20293
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 12 SP4) (Important)
    2021-09-16
    oval:org.opensuse.security:def:55946
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:57077
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:66889
    P
    Security update for grafana (Important)
    2021-08-12
    oval:org.opensuse.security:def:63344
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2255
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100949
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62191
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1102
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71932
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100933
    P
    libmicrohttpd12-0.9.57-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:20281
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 12 SP4) (Important)
    2021-07-27
    oval:org.opensuse.security:def:57968
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:57470
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:70245
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:15310
    P
    gnome-keyring-3.20.0-27.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15414
    P
    libpng12-0-1.2.50-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15630
    P
    libid3tag-devel-0.15.1b-182.58 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16343
    P
    openslp-devel-2.0.0-17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15705
    P
    xen-devel-4.4.1_06-2.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15318
    P
    gtk2-data-2.24.31-7.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15509
    P
    supportutils-3.0-85.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15678
    P
    net-snmp-devel-5.7.2.1-3.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16366
    P
    systemtap-sdt-devel-3.0-10.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15465
    P
    openvswitch-2.5.1-24.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69860
    P
    Security update for pam_radius (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15344
    P
    libXcursor1-1.1.14-3.59 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15603
    P
    libXtst-devel-1.2.2-3.60 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15689
    P
    postgresql93-devel-9.3.5-2.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15485
    P
    python-cupshelpers-1.5.7-7.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:66797
    P
    Security update for slurm (Important)
    2021-05-31
    oval:org.opensuse.security:def:73580
    P
    Security update for xen (Important)
    2021-04-06
    oval:org.opensuse.security:def:57185
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:94220
    P
    (Important)
    2021-02-26
    oval:org.opensuse.security:def:20317
    P
    Security update for the Linux Kernel (Live Patch 13 for SLE 12 SP4) (Important)
    2021-02-10
    oval:org.opensuse.security:def:57389
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:42466
    P
    xen-4.2.2_04-0.7.5 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107599
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42049
    P
    sysstat-8.1.5-7.9.56 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71598
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63278
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100537
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2189
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116761
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61857
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41947
    P
    enscript-1.6.4-152.17.55 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107203
    P
    libosinfo-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117157
    P
    libosinfo-devel-1.7.1-1.52 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:66412
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:20955
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:19862
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:20190
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12) (Important)
    2020-12-01
    oval:org.opensuse.security:def:56626
    P
    Security update for ecryptfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39269
    P
    Security update for SLES 12-SP1 Docker image (Important)
    2020-12-01
    oval:org.opensuse.security:def:66504
    P
    libosinfo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57277
    P
    Security update for xorg-x11
    2020-12-01
    oval:org.opensuse.security:def:41525
    P
    Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP3) (Important)
    2020-12-01
    oval:org.opensuse.security:def:50020
    P
    libxmltooling-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:20040
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 12) (Important)
    2020-12-01
    oval:org.opensuse.security:def:56347
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:43149
    P
    Security update for libosinfo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39029
    P
    libgadu3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39577
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40435
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:19819
    P
    Security update for Linux Kernel Live Patch 15 for SLE 12 (Important)
    2020-12-01
    oval:org.opensuse.security:def:41878
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:39752
    P
    Security update for gdk-pixbuf (Low)
    2020-12-01
    oval:org.opensuse.security:def:19948
    P
    Security update for Linux Kernel Live Patch 20 for SLE 12 (Important)
    2020-12-01
    oval:org.opensuse.security:def:20223
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12) (Important)
    2020-12-01
    oval:org.opensuse.security:def:38934
    P
    telepathy-gabble on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56792
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39327
    P
    Security update for java-1_6_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57351
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:49209
    P
    libosinfo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41617
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:39685
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:70140
    P
    typelib-1_0-JavaScriptCore-4_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19827
    P
    Security update for Linux Kernel Live Patch 23 for SLE 12 (Important)
    2020-12-01
    oval:org.opensuse.security:def:43104
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP1) (Important)
    2020-12-01
    oval:org.opensuse.security:def:38933
    P
    rhythmbox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:20078
    P
    Security update for net-snmp (Important)
    2020-12-01
    oval:org.opensuse.security:def:73077
    P
    file on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56520
    P
    Security update for postgresql96 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39166
    P
    gnome-online-accounts on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39636
    P
    Security update for systemd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41514
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:39797
    P
    Security update for minicom (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:20006
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:50074
    P
    libosinfo-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73195
    P
    libosinfo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38945
    P
    empathy on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49155
    P
    libXvnc1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41513
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:39417
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:73462
    P
    libyaml-cpp0_6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:41769
    P
    Security update for rpcbind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39724
    P
    Security update for ceph (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:40477
    P
    Security update for libosinfo (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20201051
    P
    RHSA-2020:1051: libosinfo security and bug fix update (Low)
    2020-03-31
    oval:com.redhat.rhsa:def:20193387
    P
    RHSA-2019:3387: osinfo-db and libosinfo security and bug fix update (Low)
    2019-11-05
    oval:com.ubuntu.cosmic:def:2019133130000000
    V
    CVE-2019-13313 on Ubuntu 18.10 (cosmic) - medium.
    2019-07-05
    oval:com.ubuntu.bionic:def:2019133130000000
    V
    CVE-2019-13313 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-07-05
    oval:com.ubuntu.xenial:def:2019133130000000
    V
    CVE-2019-13313 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-07-05
    oval:com.ubuntu.disco:def:2019133130000000
    V
    CVE-2019-13313 on Ubuntu 19.04 (disco) - medium.
    2019-07-05
    BACK