Bug 48205 - systemd: Multiple issues (4.2)
systemd: Multiple issues (4.2)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.2
All Linux
: P3 normal (vote)
: UCS 4.2-5-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-11-26 16:28 CET by Quality Assurance
Modified: 2018-11-28 12:29 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 8.8 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2018-11-26 16:28:54 CET
New Debian systemd 215-17+deb8u8A~4.2.5.201811260940 fixes:
This update addresses the following issues:
* automount: access to automounted volumes can lock up (CVE-2018-1049)
* Line splitting via fgets() allows for state injection during daemon-reexec  (CVE-2018-15686)
* Out-of-bounds heap write in systemd-networkd dhcpv6 option handling  (CVE-2018-15688)
Comment 1 Quality Assurance univentionstaff 2018-11-27 12:00:23 CET
--- mirror/ftp/4.2/unmaintained/4.2-4/source/systemd_215-17+deb8u7A~4.2.3.201801211553.dsc
+++ apt/ucs_4.2-0-errata4.2-5/source/systemd_215-17+deb8u8A~4.2.5.201811260940.dsc
@@ -1,8 +1,21 @@
-215-17+deb8u7A~4.2.3.201801211553 [Wed, 24 Jan 2018 17:55:06 +0100] Univention builddaemon <buildd@univention.de>:
+215-17+deb8u8A~4.2.5.201811260940 [Mon, 26 Nov 2018 16:29:01 +0100] Univention builddaemon <buildd@univention.de>:
 
   * UCS auto build. The following patches have been applied to the original source package
     10-ignore-ucs-divered
     15-fix-mtd_probe-h
+
+215-17+deb8u8 [Tue, 13 Nov 2018 14:44:47 -0500] Antoine Beaupré <anarcat@debian.org>:
+
+  * Non-maintainer upload by the LTS Security Team.
+  * CVE-2018-1049: fix race condition between .mount and .automount
+    unitspossibly leading to Denial of Service
+  * CVE-2018-15686: fix improper serialization on upgrade which can
+    influence systemd execution environment and lead to root privilege
+    escalation (Closes: #912005)
+  * CVE-2018-15688: fix buffer overflow vulnerability in the dhcp6 client
+    of systemd, which allows a malicious dhcp6 server to overwrite heap
+    memory in systemd-networkd, leading to denial of service or potential
+    code execution. (Closes: #912008)
 
 215-17+deb8u7 [Fri, 10 Mar 2017 06:02:49 +0100] Michael Biebl <biebl@debian.org>:
 

<http://10.200.17.11/4.2-5/#937390140718657890>
Comment 2 Philipp Hahn univentionstaff 2018-11-27 12:51:33 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[4.2-5] 4d6d4400c8 Bug #48205: systemd 215-17+deb8u8A~4.2.5.201811260940
 doc/errata/staging/systemd.yaml | 18 ++++++++++++++++++
 1 file changed, 18 insertions(+)
Comment 3 Arvid Requate univentionstaff 2018-11-28 12:29:36 CET
<http://errata.software-univention.de/ucs/4.2/557.html>