In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.
Conclusion & alert: CVE-2019-12210 is rated High Exploit Risk (75.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.87%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.49% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.38% | 1.87% | +1.49% |
| 2 | 2025-03-30 | 1.20% | 0.38% | -0.82% |
| 3 | 2025-03-29 | — | 1.20% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.0 | HIGH |
|
2.8 | 5.2 | [email protected] |
| 5.5 | 2.0 | MEDIUM |
|
8.0 | 4.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2019-12210 low priority: Debian including 1 source packages (pam-u2f), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-12210 |
suse
|
medium | CVE-2019-12210 severity moderate: SUSE including 23 source package names (libu2f-host-devel-1.1.6-3.6.1, libu2f-host-devel-1.1.6-lp150.10.1, …), 54 product×package rows across 27 product lines (SUSE Linux Enterprise Desktop 12 SP4, SUSE Linux Enterprise High Performance Computing 12 SP5, … (27 product lines)): Fixed 54. | https://www.suse.com/security/cve/CVE-2019-12210/ |
ubuntu
|
medium | CVE-2019-12210 medium priority: Ubuntu including 1 source packages (pam-u2f), 18 status rows across 18 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): not-affected 14, ignored 2, DNE 1, released 1. | https://ubuntu.com/security/CVE-2019-12210 |
| URL | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html | |
| http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html | |
| http://www.openwall.com/lists/oss-security/2019/06/05/1 | Exploit Mailing List Third Party Advisory |
| https://developers.yubico.com/pam-u2f/Release_Notes.html | Release Notes Vendor Advisory |
| https://github.com/Yubico/pam-u2f/commit/18b1914e32b74ff52000f10e97067e841e5fff62 | Patch Third Party Advisory |