PT-2018-1713 · Systemd+5 · Systemd+5
Felix Wilhelm
·
Publicado
2018-10-14
·
Atualizado
2024-06-15
·
CVE-2018-15688
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
systemd versions up to and including 239
Description:
The issue is caused by incorrect size checking of a temporary buffer in the dhcp6 option append ia() function of the Systemd daemon. This can be exploited by a remote attacker using a specially crafted packet sent to the DHCPv6 server, potentially allowing the execution of arbitrary code or causing a denial of service. The vulnerability affects the dhcp6 client in systemd, allowing a malicious dhcp6 server to overwrite heap memory in systemd-networkd.
Recommendations:
For versions up to and including 239, update to a version that includes a fix for this issue to prevent potential exploitation.
Correção
Integer Overflow
Buffer Overflow
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Systemd