CVE-2019-20795
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
iproute2 versiones anteriores a 5.1.0, presenta un uso de la memoria previamente liberada en la función get_netnsid_from_name en el archivo ip/ipnetns.c. NOTA: la relevancia para la seguridad puede limitarse a ciertos usos del setuid que, aunque no es un valor predeterminado, a veces es una opción de configuración ofrecida a los usuarios finales. Incluso cuando se utiliza setuid, otros factores (como la configuración de la biblioteca C) pueden bloquear la posibilidad de explotación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-09 CVE Reserved
- 2020-05-09 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1171452 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/?id=9bf2c538a0eb10d66e2365a655bf6c52f5ba3d10 | 2020-09-10 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202008-06 | 2020-09-10 | |
https://usn.ubuntu.com/4357-1 | 2020-09-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Iproute2 Project Search vendor "Iproute2 Project" | Iproute2 Search vendor "Iproute2 Project" for product "Iproute2" | < 5.1.0 Search vendor "Iproute2 Project" for product "Iproute2" and version " < 5.1.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04" | lts |
Affected
|