ALT-PU-2019-1000-1
Closed vulnerabilities
BDU:2018-01289
Уязвимость функции dhcp6_option_append_ia() демона Systemd, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2019-00414
Уязвимость в бинарной системе хранения служебной информации systemd-journald операционной системы Debian, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2019-01413
Уязвимость функции bus_process_object() подсистемы инициализации операционных систем Linux Systemd, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-01963
Уязвимость компонента unit_deserialize демона Systemd, позволяющая нарушителю повысить свои привилегии до уровня root
BDU:2022-03137
Уязвимость функции chown_one() подсистемы инициализации и управления службами systemd, позволяющая нарушителю повысить свои привилегии
Modified: 2024-11-21
CVE-2018-15686
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
- 105747
- 105747
- RHSA-2019:2091
- RHSA-2019:2091
- RHSA-2019:3222
- RHSA-2019:3222
- RHSA-2020:0593
- RHSA-2020:0593
- https://github.com/systemd/systemd/pull/10519
- https://github.com/systemd/systemd/pull/10519
- [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image
- [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image
- [debian-lts-announce] 20181119 [SECURITY] [DLA 1580-1] systemd security update
- [debian-lts-announce] 20181119 [SECURITY] [DLA 1580-1] systemd security update
- GLSA-201810-10
- GLSA-201810-10
- USN-3816-1
- USN-3816-1
- 45714
- 45714
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
Modified: 2024-11-21
CVE-2018-15687
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
Modified: 2024-11-21
CVE-2018-15688
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
- 105745
- 105745
- RHBA-2019:0327
- RHBA-2019:0327
- RHSA-2018:3665
- RHSA-2018:3665
- RHSA-2019:0049
- RHSA-2019:0049
- https://github.com/systemd/systemd/pull/10518
- https://github.com/systemd/systemd/pull/10518
- [debian-lts-announce] 20181119 [SECURITY] [DLA 1580-1] systemd security update
- [debian-lts-announce] 20181119 [SECURITY] [DLA 1580-1] systemd security update
- GLSA-201810-10
- GLSA-201810-10
- USN-3806-1
- USN-3806-1
- USN-3807-1
- USN-3807-1
Modified: 2024-11-21
CVE-2018-16866
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
- http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
- http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
- 20190513 Re: System Down: A systemd-journald exploit
- 20190513 Re: System Down: A systemd-journald exploit
- [oss-security] 20190510 Re: System Down: A systemd-journald exploit
- [oss-security] 20190510 Re: System Down: A systemd-journald exploit
- 106527
- 106527
- RHSA-2019:2091
- RHSA-2019:2091
- RHSA-2019:3222
- RHSA-2019:3222
- RHSA-2020:0593
- RHSA-2020:0593
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866
- 20190513 Re: System Down: A systemd-journald exploit
- 20190513 Re: System Down: A systemd-journald exploit
- GLSA-201903-07
- GLSA-201903-07
- https://security.netapp.com/advisory/ntap-20190117-0001/
- https://security.netapp.com/advisory/ntap-20190117-0001/
- USN-3855-1
- USN-3855-1
- DSA-4367
- DSA-4367
- https://www.qualys.com/2019/01/09/system-down/system-down.txt
- https://www.qualys.com/2019/01/09/system-down/system-down.txt
Modified: 2024-11-21
CVE-2019-6454
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
- SUSE-SA:2019:0255-1
- openSUSE-SU-2019:1450
- [oss-security] 20190218 CVE-2019-6454: systemd (PID1) crash with specially crafted D-Bus message
- [oss-security] 20190219 CVE-2019-6454: systemd (PID1) crash with specially crafted D-Bus message
- [oss-security] 20210720 CVE-2021-33910: Denial of service (stack exhaustion) in systemd (PID 1)
- 107081
- RHSA-2019:0368
- RHSA-2019:0990
- RHSA-2019:1322
- RHSA-2019:1502
- RHSA-2019:2805
- https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c
- https://kc.mcafee.com/corporate/index?page=content&id=SB10278
- [SECURITY] [DLA 1684-1] 20190219 systemd security update
- FEDORA-2019-8434288a24
- https://security.netapp.com/advisory/ntap-20190327-0004/
- USN-3891-1
- DSA-4393-1
- SUSE-SA:2019:0255-1
- DSA-4393-1
- USN-3891-1
- https://security.netapp.com/advisory/ntap-20190327-0004/
- FEDORA-2019-8434288a24
- [SECURITY] [DLA 1684-1] 20190219 systemd security update
- https://kc.mcafee.com/corporate/index?page=content&id=SB10278
- https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c
- RHSA-2019:2805
- RHSA-2019:1502
- RHSA-2019:1322
- RHSA-2019:0990
- RHSA-2019:0368
- 107081
- [oss-security] 20210720 CVE-2021-33910: Denial of service (stack exhaustion) in systemd (PID 1)
- [oss-security] 20190219 CVE-2019-6454: systemd (PID1) crash with specially crafted D-Bus message
- [oss-security] 20190218 CVE-2019-6454: systemd (PID1) crash with specially crafted D-Bus message
- openSUSE-SU-2019:1450