Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2021-0304 Critical: Systemd Privilege Escalation

mageia
Calendar Grey June 30, 2021
Dist Mageia Esm H88
A serious vulnerability in systemd for Mageia has been fixed, preventing privilege escalation via incorrectly handled usernames. Visit the advisory for full details!
A flaw was found in systemd, where it mishandles numerical usernames beginning with decimal digits, or "0x" followed by hexadecimal digits

Summary

A flaw was found in systemd, where it mishandles numerical usernames beginning with decimal digits, or "0x" followed by hexadecimal digits. When the usernames are used by systemd, for example in service units, an unexpected user may be used instead. In some particular configurations, this flaw allows local attackers to elevate their privileges (CVE-2020-13776).

References

- https://bugs.mageia.org/show_bug.cgi?id=27043

- https://access.redhat.com/errata/RHSA-2021:1611

- https://www.cve.org/CVERecord?id=CVE-2020-13776

Resolution

SRPMS

- 7/core/systemd-241-8.6.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 30 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0304.html
Type: security
CVE: CVE-2020-13776

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here