Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 9 DLA-3063-1 Critical: Systemd Heap Use-After-Free Exploit

debian lts
Calendar Grey June 30, 2022
Dist Debian Esm H88
An integer overflow vulnerability in openSSL enables remote adversaries to execute arbitrary code or disrupt services by sending malicious packets.
A heap use-after-free vulnerability was found in systemd, a system and service manager, where asynchronous Polkit queries are performed while handling dbus messages

Summary

For Debian 9 stretch, this problem has been fixed in version
232-25+deb9u14.

We recommend that you upgrade your systemd packages.

For the detailed security status of systemd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/systemd

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: systemd
Version: 232-25+deb9u14
CVE ID: CVE-2020-1712
Debian Bug: 950732

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here