Total vulnerabilities in the database
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Software | From | Fixed in |
---|---|---|
systemd_project / systemd | - | 244.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / openshift_container_platform | 4.0 | 4.0.x |
redhat / migration_toolkit | 1.0 | 1.0.x |
redhat / ceph_storage | 4.0 | 4.0.x |
debian / debian_linux | 9.0 | 9.0.x |