First published: Thu Sep 20 2012(Updated: )
A possibility for denial of loggin service was found in the way journald functionality of systemd, a system and service manager, processed native messages when file was chosen as their origin. A local attacker could use this flaw to provide a specially-crafted file descriptor, leading the journald file read process to block, resultingin portion of subsequent native messages intended to be logged to be ignored. Issue found by Florian Weimer, Red Hat Product Security Team
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
systemd | <194 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4393 has been classified as a medium severity vulnerability.
To mitigate CVE-2013-4393, upgrade systemd to version 194 or later.
CVE-2013-4393 affects users of systemd versions prior to 194.
CVE-2013-4393 is a denial of service vulnerability in the journald functionality of systemd.
CVE-2013-4393 can only be exploited by a local attacker with access to the affected system.