Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Improper Input Validation systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.
Remediation
There is no fixed version for systemd
.
References
CVSS Score
6.7
low severity
-
Attack VectorLocal
-
Attack ComplexityHigh
-
Privileges RequiredLow
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-13776
- CWE
- CWE-20
- Snyk ID
- SNYK-UBUNTU1604-SYSTEMD-573077
- Disclosed
- 03 Jun, 2020
- Published
- 03 Jun, 2020