CVE-2015-8842: Low severity suse linux vulnerability
Published Apr 20, 2016
·Updated
tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.
Affected Software
1 affected component
openSUSE openSUSE=13.2
Event History
Apr 20, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8842?
CVE-2015-8842 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2015-8842?
To fix CVE-2015-8842, update systemd to version 229 or later, which addresses the weak permissions issue.
3
Who is affected by CVE-2015-8842?
CVE-2015-8842 affects users of openSUSE 13.2 with vulnerable versions of systemd.
4
What are the risks associated with CVE-2015-8842?
The risks associated with CVE-2015-8842 include unauthorized local access to sensitive log data located in the system journal.
5
Is CVE-2015-8842 exploitable remotely?
CVE-2015-8842 is not remotely exploitable as it requires local access to the affected system.