CVE-2020-1712
published 2020-03-31CVE-2020-1712: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.46%
37.0th percentile
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | systemd | < systemd 244.2-1 (bookworm) | systemd 244.2-1 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-34_on_cbl_mariner_1.0 | — | — |
| redhat | ceph_storage | — | — |
| redhat | enterprise_linux | — | — |
| redhat | migration_toolkit | — | — |
| redhat | openshift_container_platform | — | — |
| systemd_project | systemd | <= 244 | — |
| systemd_project | systemd | >= 0 < 244.2-1 | 244.2-1 |
| systemd_project | systemd | >= 0 < 244.2-1 | 244.2-1 |
| systemd_project | systemd | >= 0 < 244.2-1 | 244.2-1 |
| systemd_project | systemd | >= 0 < 244.2-1 | 244.2-1 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.27 | 229-4ubuntu21.27 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.38 | 237-3ubuntu10.38 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Microsoft
A heap use-after-free vulnerability was found in systemd before version v245-rc1 where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse t
vendor_msrc·2020-03-10·CVSS 7.8
CVE-2020-1712 [HIGH] CWE-416 A heap use-after-free vulnerability was found in systemd before version v245-rc1 where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse t
A heap use-after-free vulnerability was found in systemd before version v245-rc1 where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges by sending specially crafted dbus messages.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishin
Red Hat
systemd: use-after-free when asynchronous polkit queries are performed
vendor_redhat·2020-02-05·CVSS 7.8
CVE-2020-1712 [HIGH] CWE-416 systemd: use-after-free when asynchronous polkit queries are performed
systemd: use-after-free when asynchronous polkit queries are performed
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
A heap use-after-free vulnerability was found in systemd, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Statement: This issue did not affect the versions of systemd as shipped wi
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2020-02-05·CVSS 4.7
CVE-2018-16888 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd incorrectly handled certain PIDFile files.
A local attacker could possibly use this issue to trick systemd into
killing privileged processes. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16888)
It was discovered that systemd incorrectly handled certain udevadm trigger
commands. A local attacker could possibly use this issue to cause systemd
to consume resources, leading to a denial of service. (CVE-2019-20386)
Jann Horn discovered that systemd incorrectly handled services that use the
DynamicUser property. A local attacker could possibly use this issue to
access resources owned by a different service in the future. This issue
only affected Ubuntu 18.04 LTS. (CVE
Debian
CVE-2020-1712: systemd - A heap use-after-free vulnerability was found in systemd before version v245-rc1...
vendor_debian·2020·CVSS 7.8
CVE-2020-1712 [HIGH] CVE-2020-1712: systemd - A heap use-after-free vulnerability was found in systemd before version v245-rc1...
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Scope: local
bookworm: resolved (fixed in 244.2-1)
bullseye: resolved (fixed in 244.2-1)
forky: resolved (fixed in 244.2-1)
sid: resolved (fixed in 244.2-1)
trixie: resolved (fixed in 244.2-1)
GHSA
GHSA-wggx-8wf7-vg3g: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus
ghsa_unreviewed·2022-05-24
CVE-2020-1712 [MEDIUM] CWE-416 GHSA-wggx-8wf7-vg3g: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
OSV
CVE-2020-1712: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus
osv·2020-03-31·CVSS 7.8
CVE-2020-1712 [HIGH] CVE-2020-1712: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
OSV
systemd vulnerabilities
osv·2020-02-05·CVSS 4.7
CVE-2018-16888 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd incorrectly handled certain PIDFile files.
A local attacker could possibly use this issue to trick systemd into
killing privileged processes. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16888)
It was discovered that systemd incorrectly handled certain udevadm trigger
commands. A local attacker could possibly use this issue to cause systemd
to consume resources, leading to a denial of service. (CVE-2019-20386)
Jann Horn discovered that systemd incorrectly handled services that use the
DynamicUser property. A local attacker could possibly use this issue to
access resources owned by a different service in the future. This issue
only affected Ubuntu 18.04 LTS. (CVE-2019-3843, CVE-2019-3844)
Tavis Ormandy discovered that system
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27757 ImageMagick: outside the range of representable values of type 'unsigned long long' at MagickCore/quantum-private.h
bugzilla·2020-11-03·CVSS 3.3
CVE-2020-27757 [LOW] CVE-2020-27757 ImageMagick: outside the range of representable values of type 'unsigned long long' at MagickCore/quantum-private.h
CVE-2020-27757 ImageMagick: outside the range of representable values of type 'unsigned long long' at MagickCore/quantum-private.h
In ImageMagick, there is an outside the range of representable values of type 'unsigned long long' bug at MagickCore/quantum-private.h.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1712
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/e88532bd4418e95b70cbc415fe911d22ab27a5fd
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Flaw summary:
A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavior in the form of a value outside the range of type unsigned long long. The flaw could be triggered by a crafted input file under certain
Bugzilla
CVE-2020-1712 systemd: use-after-free when asynchronous polkit queries are performed [fedora-all]
bugzilla·2020-02-05·CVSS 7.8
CVE-2020-1712 [HIGH] CVE-2020-1712 systemd: use-after-free when asynchronous polkit queries are performed [fedora-all]
CVE-2020-1712 systemd: use-after-free when asynchronous polkit queries are performed [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2020-1712 systemd: use-after-free when asynchronous polkit queries are performed
bugzilla·2020-01-23·CVSS 7.8
CVE-2020-1712 [HIGH] CVE-2020-1712 systemd: use-after-free when asynchronous polkit queries are performed
CVE-2020-1712 systemd: use-after-free when asynchronous polkit queries are performed
systemd contains a heap use-after-free vulnerability due to the way asynchronous polkit queries are performed. The userdata that needs to be passed to the polkit callback is cached in the AsyncPolkitQuery structure, however when the callback is actually called, the object the userdata is pointing to may already have been released and re-used for other purposes. Local unprivileged attackers may abuse this flaw to crash systemd services or potentially execute code and elevate their privileges.
Discussion:
This bug happens due to the way bus_verify_polkit_async() works. Some DBus interfaces use a cache to store objects for a short period and they clear it as soon as the bus is again in the idle state. Howe
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abbhttps://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2dhttps://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2https://lists.debian.org/debian-lts-announce/2022/06/msg00025.htmlhttps://www.openwall.com/lists/oss-security/2020/02/05/1https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abbhttps://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2dhttps://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2https://lists.debian.org/debian-lts-announce/2022/06/msg00025.htmlhttps://www.openwall.com/lists/oss-security/2020/02/05/1
2020-03-31
Published