cbcvebase.
CVE-2020-1712
published 2020-03-31

CVE-2020-1712: A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansystemd< systemd 244.2-1 (bookworm)systemd 244.2-1 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-34_on_cbl_mariner_1.0
redhatceph_storage
redhatenterprise_linux
redhatmigration_toolkit
redhatopenshift_container_platform
systemd_projectsystemd<= 244
systemd_projectsystemd>= 0 < 244.2-1244.2-1
systemd_projectsystemd>= 0 < 244.2-1244.2-1
systemd_projectsystemd>= 0 < 244.2-1244.2-1
systemd_projectsystemd>= 0 < 244.2-1244.2-1
systemd_projectsystemd>= 0 < 229-4ubuntu21.27229-4ubuntu21.27
systemd_projectsystemd>= 0 < 237-3ubuntu10.38237-3ubuntu10.38

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH