Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Debian 9 DLA-3063-1 Critical: Systemd Heap Use-After-Free Exploit

debian lts
Calendar Grey June 30, 2022
Scroller Debian Lts
An integer overflow vulnerability in openSSL enables remote adversaries to execute arbitrary code or disrupt services by sending malicious packets.
A heap use-after-free vulnerability was found in systemd, a system and service manager, where asynchronous Polkit queries are performed while handling dbus messages

Summary

For Debian 9 stretch, this problem has been fixed in version
232-25+deb9u14.

We recommend that you upgrade your systemd packages.

For the detailed security status of systemd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/systemd

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: systemd
Version: 232-25+deb9u14
CVE ID: CVE-2020-1712
Debian Bug: 950732

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.