Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20386

Опубликовано: 22 янв. 2020
Источник: redhat
CVSS3: 2.4
EPSS Низкий

Описание

An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.

A memory leak was discovered in the systemd-login when a power-switch event is received. A physical attacker may trigger one of these events and leak bytes due to a missing free.

Отчет

The version of systemd delivered in OpenShift Container Platform 4.1 and included in CoreOS images has been superseded by the version delivered in Red Hat Enterprise Linux 8. CoreOS updates for systemd in will be consumed from Red Hat Enterprise Linux 8 channels.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4systemdWill not fix
Red Hat Enterprise Linux 7systemdFixedRHSA-2020:400729.09.2020
Red Hat Enterprise Linux 8systemdFixedRHSA-2020:455304.11.2020
Red Hat OpenShift Doopenshiftdo/odo-init-image-rhel7FixedRHSA-2021:094922.03.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1793979systemd: memory leak in button_open() in login/logind-button.c when udev events are received

EPSS

Процентиль: 36%
0.00152
Низкий

2.4 Low

CVSS3

Связанные уязвимости

CVSS3: 2.4
ubuntu
около 6 лет назад

An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.

CVSS3: 2.4
nvd
около 6 лет назад

An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.

CVSS3: 2.4
msrc
больше 5 лет назад

An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command a memory leak may occur.

CVSS3: 2.4
debian
около 6 лет назад

An issue was discovered in button_open in login/logind-button.c in sys ...

suse-cvrf
больше 5 лет назад

Security update for systemd

EPSS

Процентиль: 36%
0.00152
Низкий

2.4 Low

CVSS3