漏洞信息详情
systemd-journald 缓冲区错误漏洞
漏洞简介
systemd是德国软件开发者Lennart Poettering和其他人共同研发的一款基于Linux的系统和服务管理器,它兼容了SysV和LSB的启动脚本,且提供了一个用来表示系统服务间依赖关系的框架。systemd-journald是其中的一个用于收集和存储日志数据的系统服务。
systemd-journald v221版本至v239版本中对日志消息解析的方法存在越界读取漏洞。本地攻击者可利用该漏洞泄露进程内存的数据。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/systemd/systemd/issues/9829
参考网址
来源:www.securityfocus.com
链接:http://www.securityfocus.com/bid/106527
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/3855-1/
来源:www.qualys.com
链接:https://www.qualys.com/2019/01/09/system-down/system-down.txt
来源:DEBIAN
链接:https://www.debian.org/security/2019/dsa-4367
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2019/05/10/4
来源:FULLDISC
链接:http://seclists.org/fulldisclosure/2019/May/21
来源:GENTOO
链接:https://security.gentoo.org/glsa/201903-07
来源:BUGTRAQ
链接:https://seclists.org/bugtraq/2019/May/25
来源:MISC
链接:http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20190117-0001/
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:3222
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:2091
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/153919/Red-Hat-Security-Advisory-2019-2091-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0682/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2969/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1170/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152047/Gentoo-Linux-Security-Advisory-201903-07.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10881778
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79514
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156526/Red-Hat-Security-Advisory-2020-0593-01.html
受影响实体
暂无
补丁
- systemd-journald 缓冲区错误漏洞的修复措施<!--2019-1-14-->
还没有评论,来说两句吧...