ALT-PU-2018-1110-1
Closed vulnerabilities
Modified: 2024-11-28
BDU:2020-04524
Уязвимость программы systemd-tmpfiles демона Systemd, позволяющая нарушителю обойти существующие ограничения доступа и раскрыть защищаемую информацию
Modified: 2025-04-20
CVE-2017-15908
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.
- http://www.securityfocus.com/bid/101600
- http://www.securitytracker.com/id/1039662
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351
- https://github.com/systemd/systemd/pull/7184
- https://usn.ubuntu.com/3558-1/
- http://www.securityfocus.com/bid/101600
- http://www.securitytracker.com/id/1039662
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351
- https://github.com/systemd/systemd/pull/7184
- https://usn.ubuntu.com/3558-1/
Modified: 2024-11-21
CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
- http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html
- http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.html
- http://www.openwall.com/lists/oss-security/2018/01/29/3
- https://github.com/systemd/systemd/issues/7736
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html
- https://www.exploit-db.com/exploits/43935/
- https://www.openwall.com/lists/oss-security/2018/01/29/4
- http://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html
- http://packetstormsecurity.com/files/146184/systemd-Local-Privilege-Escalation.html
- http://www.openwall.com/lists/oss-security/2018/01/29/3
- https://github.com/systemd/systemd/issues/7736
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html
- https://www.exploit-db.com/exploits/43935/
- https://www.openwall.com/lists/oss-security/2018/01/29/4
Modified: 2024-11-21
CVE-2018-16888
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged processes. Versions before v237 are vulnerable.
- https://access.redhat.com/errata/RHSA-2019:2091
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16888
- https://lists.apache.org/thread.html/5960a34a524848cd722fd7ab7e2227eac10107b0f90d9d1e9c3caa74%40%3Cuser.cassandra.apache.org%3E
- https://security.netapp.com/advisory/ntap-20190307-0007/
- https://usn.ubuntu.com/4269-1/
- https://access.redhat.com/errata/RHSA-2019:2091
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16888
- https://lists.apache.org/thread.html/5960a34a524848cd722fd7ab7e2227eac10107b0f90d9d1e9c3caa74%40%3Cuser.cassandra.apache.org%3E
- https://security.netapp.com/advisory/ntap-20190307-0007/
- https://usn.ubuntu.com/4269-1/