ISOMAN

CVE

CVE-2018-15686

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://www.securityfocus.com/bid/105747
  2. https://access.redhat.com/errata/RHSA-2019:2091
  3. https://access.redhat.com/errata/RHSA-2019:3222
  4. https://access.redhat.com/errata/RHSA-2020:0593
  5. https://github.com/systemd/systemd/pull/10519
  6. https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
  7. https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html
  8. https://security.gentoo.org/glsa/201810-10
  9. https://usn.ubuntu.com/3816-1/
  10. https://www.exploit-db.com/exploits/45714/
  11. https://www.oracle.com//security-alerts/cpujul2021.html
  12. http://www.securityfocus.com/bid/105747
  13. https://access.redhat.com/errata/RHSA-2019:2091
  14. https://access.redhat.com/errata/RHSA-2019:3222
  15. https://access.redhat.com/errata/RHSA-2020:0593
  16. https://github.com/systemd/systemd/pull/10519
  17. https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
  18. https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html
  19. https://security.gentoo.org/glsa/201810-10
  20. https://usn.ubuntu.com/3816-1/