Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Use After Free iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
Remediation
Upgrade iproute2
to version or higher.
References
CVSS Score
4.4
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredHigh
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2019-20795
- CWE
- CWE-416
- Snyk ID
- SNYK-ALPINE310-IPROUTE2-588873
- Disclosed
- 09 May, 2020
- Published
- 21 Jul, 2020