CVE-2018-16864
11.01.2019, 20:29
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.Enginsight
Vendor | Product | Version |
---|---|---|
systemd_project | systemd | 𝑥 ≤ 240 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server | 7.4 |
redhat | enterprise_linux_server | 7.5 |
redhat | enterprise_linux_server | 7.6 |
redhat | enterprise_linux_server_aus | 7.3 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_eus | 7.4 |
redhat | enterprise_linux_server_eus | 7.6 |
redhat | enterprise_linux_server_tus | 7.3 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_workstation | 7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
oracle | communications_session_border_controller | 8.0.0 |
oracle | communications_session_border_controller | 8.1.0 |
oracle | communications_session_border_controller | 8.2.0 |
oracle | enterprise_communications_broker | 3.0.0 |
oracle | enterprise_communications_broker | 3.1.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References