PT-2019-1257 · Systemd+5 · Systemd-Journald+5

Laura Pardo

·

Published

2019-01-01

·

Updated

2023-02-13

·

CVE-2018-16866

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions systemd-journald versions v221 through v239
Description An out of bounds read was discovered in the way systemd-journald parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. The issue is related to an error in handling messages that end with a colon, which may lead to the disclosure of memory data.
Recommendations For versions v221 through v239, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the log parsing functionality until a patch is available.

Exploit

Fix

Information Disclosure

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1000
BDU:2019-00414
CESA-2019_2091
CVE-2018-16866
DSA-4367-1
DSA-4367-2
OPENSUSE-SU-2019:0098-1
OPENSUSE-SU-2019_0097-1
OPENSUSE-SU-2019_0098-1
RHSA-2019:2091
RHSA-2019:3222
RHSA-2019_2091
RHSA-2020:0593
RHSA-2020:1264
SUSE-SU-2019:0135-1
SUSE-SU-2019:0137-1
USN-3855-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Systemd-Journald