VYPR

rpm package

opensuse/systemd-mini&distro=openSUSE Leap 15.0

pkg:rpm/opensuse/systemd-mini&distro=openSUSE%20Leap%2015.0

Vulnerabilities (5)

  • CVE-2019-6454Mar 17, 2019
    affected < 234-lp150.20.15.1fixed 234-lp150.20.15.1

    An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a speciall

  • CVE-2018-16865Jan 11, 2019
    affected < 234-lp150.20.12.1fixed 234-lp150.20.12.1

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw

  • CVE-2018-16864Jan 11, 2019
    affected < 234-lp150.20.12.1fixed 234-lp150.20.12.1

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate hi

  • CVE-2018-16866Jan 11, 2019
    affected < 234-lp150.20.12.1fixed 234-lp150.20.12.1

    An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.

  • CVE-2018-6954Feb 13, 2018
    affected < 234-lp150.20.12.1fixed 234-lp150.20.12.1

    systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory w