CVE-2019-20795
published 2020-05-09CVE-2019-20795: iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.40%
33.1th percentile
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | iproute2 | < iproute2 5.2.0-1 (bookworm) | iproute2 5.2.0-1 (bookworm) |
| iproute2_project | iproute2 | < 5.1.0 | 5.1.0 |
| iproute2_project | iproute2 | >= 0 < 5.2.0-1 | 5.2.0-1 |
| iproute2_project | iproute2 | >= 0 < 5.2.0-1 | 5.2.0-1 |
| iproute2_project | iproute2 | >= 0 < 5.2.0-1 | 5.2.0-1 |
| iproute2_project | iproute2 | >= 0 < 5.2.0-1 | 5.2.0-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
IPRoute vulnerability
vendor_ubuntu·2020-05-13
CVE-2019-20795 IPRoute vulnerability
Title: IPRoute vulnerability
Summary: IPRoute could be made to execute arbitrary code if it received a specially
crafted input.
It was discovered that IPRoute incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c
vendor_redhat·2019-05-05·CVSS 4.4
CVE-2019-20795 [MEDIUM] CWE-416 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c
iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
A use-after-free flaw was found in iproute in the network namespace management component of the ip command-line utility. This flaw allows a local attacker to crash the program while displaying network namespaces. The highest threat from this vulnerability is to system availability.
Statement: This issue affects the versions of `iproute` as shipped with Red Hat Enterprise Linux 7. Red Hat E
Debian
CVE-2019-20795: iproute2 - iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetn...
vendor_debian·2019·CVSS 4.4
CVE-2019-20795 [MEDIUM] CVE-2019-20795: iproute2 - iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetn...
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
Scope: local
bookworm: resolved (fixed in 5.2.0-1)
bullseye: resolved (fixed in 5.2.0-1)
forky: resolved (fixed in 5.2.0-1)
sid: resolved (fixed in 5.2.0-1)
trixie: resolved (fixed in 5.2.0-1)
GHSA
GHSA-7x5p-w7r4-hq6m: iproute2 before 5
ghsa_unreviewed·2022-05-24
CVE-2019-20795 [HIGH] GHSA-7x5p-w7r4-hq6m: iproute2 before 5
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c.
OSV
CVE-2019-20795: iproute2 before 5
osv·2020-05-09·CVSS 4.4
CVE-2019-20795 [MEDIUM] CVE-2019-20795: iproute2 before 5
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20795 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c [fedora-all]
bugzilla·2020-08-12·CVSS 4.4
CVE-2019-20795 [MEDIUM] CVE-2019-20795 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c [fedora-all]
CVE-2019-20795 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2019-20795 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c
bugzilla·2020-08-12·CVSS 4.4
CVE-2019-20795 [MEDIUM] CVE-2019-20795 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c
CVE-2019-20795 iproute: use-after-free in get_netnsid_from_name in ip/ipnetns.c
A vulnerability was found in iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
References:
https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/?id=9bf2c538a0eb10d66e2365a655bf6c52f5ba3d10
Discussion:
Created iproute tracking bugs for this issue:
Affects: fedora-all [bug 1868213]
---
From upstream commit:
"""
In get_netnsid_from_name func, answer is freed before
rta_getattr_u32(tb[NETNSA_NSID]), where tb[
https://bugzilla.suse.com/show_bug.cgi?id=1171452https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/?id=9bf2c538a0eb10d66e2365a655bf6c52f5ba3d10https://security.gentoo.org/glsa/202008-06https://usn.ubuntu.com/4357-1/https://bugzilla.suse.com/show_bug.cgi?id=1171452https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/?id=9bf2c538a0eb10d66e2365a655bf6c52f5ba3d10https://security.gentoo.org/glsa/202008-06https://usn.ubuntu.com/4357-1/
2020-05-09
Published