[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4428-1 systemd -- systemd

ID: oval:org.secpod.oval:def:54394Date: (C)2019-04-22   (M)2022-11-30
Class: PATCHFamily: unix




Jann Horn discovered that the PAM module in systemd insecurely uses the environment and lacks seat verification permitting spoofing an active session to PolicyKit. A remote attacker with SSH access can take advantage of this issue to gain PolicyKit privileges that are normally only granted to clients in an active session on the local console.

Platform:
Linux Mint 3
Product:
systemd
Reference:
DSA-4428-1
CVE-2019-3842
CVE    1
CVE-2019-3842
CPE    2
cpe:/a:ubuntu_developers:systemd
cpe:/o:linux_mint:linux_mint:3

© SecPod Technologies