Use After Free Affecting systemd package, versions <232-25+deb9u14
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN9-SYSTEMD-546478
- published 5 Feb 2020
- disclosed 31 Mar 2020
Introduced: 5 Feb 2020
CVE-2020-1712 Open this link in a new tabHow to fix?
Upgrade Debian:9
systemd
to version 232-25+deb9u14 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream systemd
package and not the systemd
package as distributed by Debian
.
See How to fix?
for Debian:9
relevant fixed versions and status.
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.