MGASA-2020-0094

Source
https://advisories.mageia.org/MGASA-2020-0094.html
Import Source
https://advisories.mageia.org/MGASA-2020-0094.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0094
Related
Published
2020-02-21T23:06:01Z
Modified
2020-02-21T22:40:07Z
Summary
Updated systemd packages fix security vulnerabilities
Details

Updated systemd packages fix security vulnerabilities:

It was discovered that systemd incorrectly handled certain udevadm trigger commands. A local attacker could possibly use this issue to cause systemd to consume resources, leading to a denial of service (CVE-2019-20386).

Tavis Ormandy discovered that systemd incorrectly handled certain Polkit queries. A local attacker could use this issue to cause systemd to crash, resulting in a denial of service, or possibly execute arbitrary code and escalate privileges (CVE-2020-1712).

References
Credits

Affected packages

Mageia:7 / systemd

Package

Name
systemd
Purl
pkg:rpm/mageia/systemd?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
241-8.5.mga7

Ecosystem specific

{
    "section": "core"
}