![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.4.2019.0426.1 |
Category: | SuSE Local Security Checks |
Title: | SUSE: Security Advisory (SUSE-SU-2019:0426-1) |
Summary: | The remote host is missing an update for the 'systemd' package(s) announced via the SUSE-SU-2019:0426-1 advisory. |
Description: | Summary: The remote host is missing an update for the 'systemd' package(s) announced via the SUSE-SU-2019:0426-1 advisory. Vulnerability Insight: This update for systemd fixes the following issues: CVE-2019-6454: Overlong DBUS messages could be used to crash systemd (bsc#1125352) units: make sure initrd-cleanup.service terminates before switching to rootfs (bsc#1123333) logind: fix bad error propagation login: log session state 'closing' (as well as New/Removed) logind: fix borked r check login: don't remove all devices from PID1 when only one was removed login: we only allow opening character devices login: correct comment in session_device_free() login: remember that fds received from PID1 need to be removed eventually login: fix FDNAME in call to sd_pid_notify_with_fds() logind: fd 0 is a valid fd logind: rework sd_eviocrevoke() logind: check file is device node before using .st_rdev logind: use the new FDSTOREREMOVE=1 sd_notify() message (bsc#1124153) core: add a new sd_notify() message for removing fds from the FD store again logind: make sure we don't trip up on half-initialized session devices (bsc#1123727) fd-util: accept that kcmp might fail with EPERM/EACCES core: Fix use after free case in load_from_path() (bsc#1121563) core: include Found state in device dumps device: fix serialization and deserialization of DeviceFound fix path in btrfs rule (#6844) assemble multidevice btrfs volumes without external tools (#6607) (bsc#1117025) Update systemd-system.conf.xml (bsc#1122000) units: inform user that the default target is started after exiting from rescue or emergency mode core: free lines after reading them (bsc#1123892) sd-bus: if we receive an invalid dbus message, ignore and proceeed automount: don't pass non-blocking pipe to kernel. Affected Software/OS: 'systemd' package(s) on SUSE Linux Enterprise Module for Basesystem 15, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15. Solution: Please install the updated package(s). CVSS Score: 4.9 CVSS Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2019-6454 BugTraq ID: 107081 http://www.securityfocus.com/bid/107081 Debian Security Information: DSA-4393-1 (Google Search) https://www.debian.org/security/2019/dsa-4393 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/ https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.c https://lists.debian.org/debian-lts-announce/2019/02/msg00031.html http://www.openwall.com/lists/oss-security/2019/02/18/3 http://www.openwall.com/lists/oss-security/2019/02/19/1 http://www.openwall.com/lists/oss-security/2021/07/20/2 RedHat Security Advisories: RHSA-2019:0368 https://access.redhat.com/errata/RHSA-2019:0368 RedHat Security Advisories: RHSA-2019:0990 https://access.redhat.com/errata/RHSA-2019:0990 RedHat Security Advisories: RHSA-2019:1322 https://access.redhat.com/errata/RHSA-2019:1322 RedHat Security Advisories: RHSA-2019:1502 https://access.redhat.com/errata/RHSA-2019:1502 RedHat Security Advisories: RHSA-2019:2805 https://access.redhat.com/errata/RHSA-2019:2805 SuSE Security Announcement: SUSE-SA:2019:0255-1 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.html SuSE Security Announcement: openSUSE-SU-2019:1450 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html https://usn.ubuntu.com/3891-1/ |
Copyright | Copyright (C) 2021 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |