Mark CVE-2019-384{3,4}/systemd as no-dsa
Attack vector requires control both of an exploitable service and a helper outside. Futhermore DynamicUsers are not widely used. As per https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1814596/comments/7 in Debian itself those are yet limited, but still present. The version in stretch (v232) is the version introducing support for DynamicUsers, earlier versions as for jessie mght thus even not be affected but would need to be checked.
Loading
Please register or sign in to comment