CVE-2019-19191

Publication date 21 November 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

Description

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.

Read the notes from the security team

Status

Package Ubuntu Release Status
shibboleth-sp 20.10 groovy
Not affected
20.04 LTS focal
Not affected
19.10 eoan Ignored end of life
19.04 disco Ignored end of life
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Notes


ebarretto

According to Debian: This is an issue in the upstream provided spec file which is not relevant for the binary packages build in Debian (fixed upstream in 3.1.0). The postinst in the Debian packaging does not have similar problematic chown logic.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.8 · High

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities