Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1712

Опубликовано: 31 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6
CVSS3: 7.8

Описание

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

РелизСтатусПримечание
bionic

released

237-3ubuntu10.38
devel

released

244.1-0ubuntu3
eoan

released

242-7ubuntu3.6
esm-infra-legacy/trusty

needed

esm-infra/bionic

released

237-3ubuntu10.38
esm-infra/focal

released

244.1-0ubuntu3
esm-infra/xenial

released

229-4ubuntu21.27
focal

released

244.1-0ubuntu3
groovy

released

244.1-0ubuntu3
hirsute

released

244.1-0ubuntu3

Показывать по

EPSS

Процентиль: 29%
0.00104
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
около 6 лет назад

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

CVSS3: 7.8
nvd
почти 6 лет назад

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

CVSS3: 7.8
msrc
больше 5 лет назад

A heap use-after-free vulnerability was found in systemd before version v245-rc1 where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges by sending specially crafted dbus messages.

CVSS3: 7.8
debian
почти 6 лет назад

A heap use-after-free vulnerability was found in systemd before versio ...

suse-cvrf
около 6 лет назад

Security update for systemd

EPSS

Процентиль: 29%
0.00104
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3