Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3821

Опубликовано: 08 июл. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

An off-by-one error flaw was found in systemd in the format_timespan() function of time-util.c. This flaw allows an attacker to supply specific values for time and accuracy, leading to a buffer overrun in format_timespan(), leading to a denial of service.

Отчет

Network Manager uses systemd's format_timespan() only via the FORMAT_TIMESPAN() macro which allocates a 64-byte buffer on the stack. The longest string representing 32bit values in seconds doesn't exceed 34 bytes (for example, "134y 10month 10w 1d 10h 10min 10s"). Since all the values are in exact seconds there is no decimal part to print. Therefore, it doesn't seem possible to trigger the buffer overflow by returning a specially crafted DHCPv6 lease, and the CVE doesn't affect Network Manager.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7NetworkManagerNot affected
Red Hat Enterprise Linux 7systemdOut of support scope
Red Hat Enterprise Linux 8NetworkManagerNot affected
Red Hat Enterprise Linux 8systemdFixedRHSA-2023:010012.01.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportsystemdFixedRHSA-2024:110505.03.2024
Red Hat Enterprise Linux 9systemdFixedRHSA-2023:033623.01.2023
Red Hat Enterprise Linux 9systemdFixedRHSA-2023:033623.01.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2139327systemd: buffer overrun in format_timespan() function

EPSS

Процентиль: 2%
0.00016
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

CVSS3: 5.5
nvd
почти 3 года назад

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

CVSS3: 5.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.5
debian
почти 3 года назад

An off-by-one Error issue was discovered in Systemd in format_timespan ...

suse-cvrf
больше 2 лет назад

Security update for systemd

EPSS

Процентиль: 2%
0.00016
Низкий

5.5 Medium

CVSS3