Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-16865.html
- systemd (229-4ubuntu21.15) xenial-security; urgency=medium
- * SECURITY UPDATE: memory corruption in journald via attacker controlled alloca
- - debian/patches/CVE-2018-16864.patch: journald: do not store the iovec
- entry for process commandline on the stack
- - CVE-2018-16864
- * SECURITY UPDATE: memory corruption in journald via attacker controlled alloca
- - debian/patches/CVE-2018-16865_1.patch: journald: set a limit on the
- number of fields (1k)
- - debian/patches/CVE-2018-16865_2.patch: journal-remote: set a limit on the
- number of fields in a message
- - CVE-2018-16865
- * SECURITY UPDATE: out-of-bounds read in journald
- - debian/patches/CVE-2018-16866.patch: journal: fix syslog_parse_identifier()
- - CVE-2018-16866
- * SECURITY UPDATE: symlink mishandling in systemd-tmpfiles
- - debian/patches/CVE-2018-6954.patch: don't resolve pathnames when traversing
- recursively through directory trees
- - debian/patches/CVE-2018-6954_2.patch: backport the remaining patches to
- resolve this completely
- - CVE-2018-6954
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement