CVE-2020-1712
31.03.2020, 17:15
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.Enginsight
Vendor | Product | Version |
---|---|---|
systemd_project | systemd | 𝑥 ≤ 244 |
redhat | ceph_storage | 4.0 |
redhat | discovery | - |
redhat | migration_toolkit | 1.0 |
redhat | openshift_container_platform | 4.0 |
redhat | enterprise_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
systemd |
|
Common Weakness Enumeration
References