VYPR
High severity7.8NVD Advisory· Published Dec 5, 2019· Updated Jun 17, 2026

CVE-2019-19522

CVE-2019-19522

Description

OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OpenBSD/OpenBSDdescription
  • OpenBSD/OpenBSDllm-fuzzy2 versions
    6.6+ 1 more
    • (no CPE)range: 6.6
    • cpe:2.3:o:openbsd:openbsd:6.6:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.