Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2020:0353-1 Important: Systemd Use-After-Free Issue

suse
Calendar Grey February 6, 2020
Dist Suse Esm H88
SUSE Security Patch for OpenSSH addresses critical vulnerabilities that improve overall software reliability and protect information integrity.
An update that solves one vulnerability and has 13 fixes is now available

Summary

This update for systemd provides the following fixes: - CVE-2020-1712 (bsc#bsc#1162108) Fix a heap use-after-free vulnerability, when asynchronous Polkit queries were performed while handling Dbus messages. A local unprivileged attacker could have abused this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted Dbus messages. - sd-bus: Deal with cookie overruns. (bsc#1150595) - rules: Add by-id symlinks for persistent memory. (bsc#1140631) - Drop the old fds used for logging and reopen them in the sub process before doing any new logging. (bsc#1154948) - Fix warnings thrown during package installation (bsc#1154043) - Fix for systemctl hanging by restart. (bsc#1139459) - man: mention that alias names are only effective after 'systemctl

References

#1106383 #1127557 #1133495 #1139459 #1140631

#1150595 #1151377 #1151506 #1154043 #1154948

#1155574 #1156482 #1159814 #1162108

Cross- CVE-2020-1712

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2020-1712.html

https://bugzilla.suse.com/1106383

https://bugzilla.suse.com/1127557

https://bugzilla.suse.com/1133495

https://bugzilla.suse.com/1139459

https://bugzilla.suse.com/1140631

https://bugzilla.suse.com/1150595

https://bugzilla.suse.com/1151377

https://bugzilla.suse.com/1151506

https://bugzilla.suse.com/1154043

https://bugzilla.suse.com/1154948

https://bugzilla.suse.com/1155574

https://bugzilla.suse.com/1156482

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0353-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here