{"id":7536,"date":"2018-10-29T00:19:29","date_gmt":"2018-10-28T23:19:29","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=7536"},"modified":"2018-10-29T00:19:29","modified_gmt":"2018-10-28T23:19:29","slug":"linux-vulnerability-cve-2018-15688-in-systemd","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/10\/29\/linux-vulnerability-cve-2018-15688-in-systemd\/","title":{"rendered":"Linux: Vulnerability CVE-2018-15688 in Systemd"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2018\/10\/29\/linux-schwachstelle-cve-2018-15688-in-systemd\/\" target=\"_blank\">German<\/a>]A vulnerability in the systemd component of some Linux distributions can be exploited over the network. A single DHCPv6 package is enough to provoke a crash or more. <\/p>\n<p><!--more--><\/p>\n<p>The Register discusses the vulnerability within <a href=\"https:\/\/www.theregister.co.uk\/AMP\/2018\/10\/26\/systemd_dhcpv6_rce\/\" target=\"_blank\">this article<\/a>. The <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-15688\" target=\"_blank\">CVE-2018-15688<\/a> vulnerability, released on October 26, 2018, is located in the DHCPv6 client of the open source system management suite, which is integrated in various variants of Linux. According to <a href=\"https:\/\/bugs.launchpad.net\/ubuntu\/+source\/systemd\/+bug\/1795921\" target=\"_blank\">this post<\/a> there is a vulnerability in the systemd-networkd DHCPv6 client (this has been completely reimplemented). The DHCPv6 client is automatically enabled on managed interfaces when IPv6 router advertising packets are received. Red Hat writes about this::<\/p>\n<blockquote>\n<p>systemd-networkd is vulnerable to an out-of-bounds heap write in the DHCPv6 client when handling options sent by network adjacent DHCP servers. A attacker could exploit this via malicious DHCP server to corrupt heap memory on client machines, resulting in a denial of service or potential code execution..<\/p>\n<\/blockquote>\n<p>In addition to Ubuntu and Red Hat Enterprise Linux, Systemd has been adopted as service manager for Debian, Fedora, CoreOS, Mint and SUSE Linux Enterprise Server. The Register writes <a href=\"https:\/\/www.theregister.co.uk\/AMP\/2018\/10\/26\/systemd_dhcpv6_rce\/\" target=\"_blank\">within this article<\/a>, however, that RHEL 7 does not use at least the vulnerable component by default. The developer of Systemd, Leonard Poettering, has already released a fix. The fix should be distributed to the affected distributions soon. Details can be found at <a href=\"https:\/\/www.theregister.co.uk\/AMP\/2018\/10\/26\/systemd_dhcpv6_rce\/\" target=\"_blank\">The Register<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]A vulnerability in the systemd component of some Linux distributions can be exploited over the network. A single DHCPv6 package is enough to provoke a crash or more.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[921,580],"tags":[637,69],"class_list":["post-7536","post","type-post","status-publish","format-standard","hentry","category-linux","category-security","tag-linux","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=7536"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7536\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=7536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=7536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=7536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}