Bug 48514 - systemd: Multiple issues (4.2)
Summary: systemd: Multiple issues (4.2)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 4.2
Hardware: All Linux
: P3 normal
Target Milestone: UCS 4.2-5-errata
Assignee: Quality Assurance
QA Contact: Philipp Hahn
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-01-23 09:34 CET by Quality Assurance
Modified: 2019-01-23 14:35 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 7.5 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2019-01-23 09:34:26 CET
New Debian systemd 215-17+deb8u9A~4.2.5.201901230934 fixes:
This update addresses the following issues:
* stack overflow when calling syslog from a command with long cmdline  (CVE-2018-16864)
* stack overflow when receiving many journald entries (CVE-2018-16865)
Comment 1 Quality Assurance univentionstaff 2019-01-23 10:01:41 CET
--- mirror/ftp/4.2/unmaintained/component/4.2-5-errata/source/systemd_215-17+deb8u8A~4.2.5.201811260940.dsc
+++ apt/ucs_4.2-0-errata4.2-5/source/systemd_215-17+deb8u9A~4.2.5.201901230934.dsc
@@ -1,8 +1,16 @@
-215-17+deb8u8A~4.2.5.201811260940 [Mon, 26 Nov 2018 16:29:01 +0100] Univention builddaemon <buildd@univention.de>:
+215-17+deb8u9A~4.2.5.201901230934 [Wed, 23 Jan 2019 09:34:31 +0100] Univention builddaemon <buildd@univention.de>:
 
   * UCS auto build. The following patches have been applied to the original source package
     10-ignore-ucs-divered
     15-fix-mtd_probe-h
+
+215-17+deb8u9 [Tue, 22 Jan 2019 15:30:45 -0500] Antoine Beaupré <anarcat@debian.org>:
+
+  * Non-maintainer upload by the Security Team.
+  * CVE-2018-16865: fix memory allocation overflow which could result in
+    crash or code execution in journald's socket (Closes: #918848).
+  * CVE-2018-16864: fix memory allocation overflow which could result in
+    crash or code execution on journald's commandline (Closes: #918841)
 
 215-17+deb8u8 [Tue, 13 Nov 2018 14:44:47 -0500] Antoine Beaupré <anarcat@debian.org>:
 

<http://10.200.17.11/4.2-5/#1271298395908729155>
Comment 2 Philipp Hahn univentionstaff 2019-01-23 10:44:56 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[4.2-5] 3f61f0c14b Bug #48514: systemd 215-17+deb8u9A~4.2.5.201901230934
 doc/errata/staging/systemd.yaml | 15 +++++++++++++++
 1 file changed, 15 insertions(+)
Comment 3 Arvid Requate univentionstaff 2019-01-23 14:35:17 CET
<http://errata.software-univention.de/ucs/4.2/587.html>