Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8842

Опубликовано: 20 апр. 2016
Источник: debian
EPSS Низкий

Описание

tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed215-1package
systemdnot-affectedwheezypackage

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=972612

  • Introduced by: https://github.com/systemd/systemd/commit/a606871da508995f5ede113a8fc6538afd98966c (v213)

  • Fixed by (for current persistent journal): https://github.com/systemd/systemd/commit/afae249efa4774c6676738ac5de6aeb4daf4889f (v229)

  • Starting with 215 Debian no longer ships tmpfiles.d/systemd.conf, so the fixup upstream added as

  • afae249efa4774c6676738ac5de6aeb4daf4889f for persistent journals is not needed for the packaged

  • version. Anyone using a custom config needs to ensure proper permissions.

EPSS

Процентиль: 21%
0.00068
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 10 лет назад

tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.

redhat
почти 10 лет назад

tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.

CVSS3: 3.3
nvd
почти 10 лет назад

tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.

CVSS3: 3.3
github
больше 3 лет назад

tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.

suse-cvrf
больше 9 лет назад

Security update for systemd

EPSS

Процентиль: 21%
0.00068
Низкий