CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-1712

HIGH
7.8
CVSS Severity Score
EPSS Score0.1130%
EPSS Percentile10.48th
Published2020年3月31日
Last Modified2024年11月21日

Vulnerability Description

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

Affected Platforms (CPE)

📦
Systemd Project

Systemd

<= 244
📦
Redhat

Ceph Storage

= 4.0
📦
Redhat

Discovery

All versions
📦
Redhat

Migration Toolkit

= 1.0
📦
Redhat

Openshift Container Platform

= 4.0
💻
Redhat

Enterprise Linux

= 8.0
💻
Debian

Debian Linux

= 9.0

References & Advisories

相关漏洞威胁