CyberSec.Space Logo
Back to CVE Browser

CVE-2020-1712

HIGH
7.8
CVSS Severity Score
EPSS Score0.1130%
EPSS Percentile10.48th
PublishedMar 31, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

Affected Platforms (CPE)

πŸ“¦
Systemd Project

Systemd

<= 244
πŸ“¦
Redhat

Ceph Storage

= 4.0
πŸ“¦
Redhat

Discovery

All versions
πŸ“¦
Redhat

Migration Toolkit

= 1.0
πŸ“¦
Redhat

Openshift Container Platform

= 4.0
πŸ’»
Redhat

Enterprise Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0

References & Advisories

Related Vulnerabilities