[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-3843 -- systemd

ID: oval:org.secpod.oval:def:1901955Date: (C)2019-06-19   (M)2023-11-13
Class: VULNERABILITYFamily: unix




It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

Platform:
Ubuntu 18.04
Product:
systemd
Reference:
CVE-2019-3843
CVE    1
CVE-2019-3843
CPE    4
cpe:/a:ubuntu_developers:systemd
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/o:ubuntu:ubuntu_linux:18.10
cpe:/o:ubuntu:ubuntu_linux:19.04
...

© SecPod Technologies