You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa systemd

Sigurnosni nedostatak programskog paketa systemd

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3806-1
November 05, 2018

systemd vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.10
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

systemd-networkd could be made to crash or run programs if it received
specially crafted network traffic.

Software Description:
– systemd: system and service manager

Details:

Felix Wilhelm discovered that the systemd-networkd DHCPv6 client
incorrectly handled certain DHCPv6 messages. In configurations where
systemd-networkd is being used, an attacker on the same network could use
this issue to cause systemd-networkd to crash, resulting in a denial of
service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
systemd 239-7ubuntu10.1

Ubuntu 18.04 LTS:
systemd 237-3ubuntu10.4

Ubuntu 16.04 LTS:
systemd 229-4ubuntu21.6

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3806-1
CVE-2018-15688

Package Information:
https://launchpad.net/ubuntu/+source/systemd/239-7ubuntu10.1
https://launchpad.net/ubuntu/+source/systemd/237-3ubuntu10.4
https://launchpad.net/ubuntu/+source/systemd/229-4ubuntu21.6

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlvgXtUACgkQZWnYVadE
vpNeiQ/+M5zgI3IA+OVr9HdU21tjfzC1VTr6nZwnDgb4W/Oe93c2BFzVmqyksaAr
Ze6RE1M+BA5ZURs8vR8CgRdJtMQLgRVEIO+m926qrm8iaNJd8Py2/hE2v2Ji+vYK
qpMJFQR+PPoN2PziYvxqpI29VRPT/J0IzCOr/RcAEnVgQUH8a6bIKp8xvG4eR1Hr
rTVeRh3mSDn6VldagC5T26VR8N5cir1SY4Mz68mIH2PLstZj57B3tzp3xQPs/kUo
icxGw/pY6yUkVd1PK0DYfjKvbnZm/O00U64QUcC9VXuK4KFerKHgWm7/frRTXRd2
OqXafMWIqtySlq7/mQQLw69AHAuNXsQyPOKe7hZRvrZGGqtwliJE3CQUlIWM8KpV
9boM4pQ6Hf6wNWcqrjmQR3a79P/fZppSm88G70kLUYJSUc8sqtuxeO9QJcTjn4rn
IIFodP4bfImxu/Hfc2mc/0KONVYZ/ggE9plNp9hqrbzjDs8h0Mye0YwTdkY8tXPz
VYSHTF4ITDGVPTbr2IIneJ8hw8vG+BTnSOhVS4wz2cY78Jrd8m3r/SVwTWqSc+FT
GiGzUbsMmTShfusWzzeUu7QH3JbG77kGxVgRi/7eg+yx/EAe0ZXL/C3sB44iNDj6
hFvJU1AgyxlzuDS7r86Wn+WW+ty1BdzGW7KFppc+hxwPzMveGhQ=
=Laiz
—–END PGP SIGNATURE—–

AutorZvonimir Bosnjak
Cert idNCERT-REF-2018-11-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa ruby

Otkriveni su sigurnosni nedostaci u programskom paketu ruby za operacijski sustav Ubuntu. Otkriveni nedostaci potencijalnim napadačima omogućuju zaobilaženje sigurnosnih ograničenja...

Close