CVE-2019-20856
published 2020-06-19CVE-2019-20856: An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.44%
70.2th percentile
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 4.4.0-161.189 | 4.4.0-161.189 |
| mattermost | mattermost_desktop | < 4.3.0 | 4.3.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jmf2-h546-v465: An issue was discovered in Mattermost Desktop App before 4
ghsa_unreviewed·2022-05-24
CVE-2019-20856 [HIGH] CWE-427 GHSA-jmf2-h546-v465: An issue was discovered in Mattermost Desktop App before 4
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-09-02·CVSS 7.8
CVE-2018-20856 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that a use-after-free error existed in the block layer
subsystem of the Linux kernel when certain failure conditions occurred. A
local attacker could possibly use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2018-20856)
Amit Klein and Benny Pinkas discovered that the Linux kernel did not
sufficiently randomize IP ID values generated for connectionless networking
protocols. A remote attacker could use this to track particular Linux
devices. (CVE-2019-10638)
Praveen Pandey discovered that the Linux kernel did not properly validate
sent signals in some situations on PowerPC systems with transactional
memory disabled. A local attacker could use this to c
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-19
Published