First published: Tue Jun 13 2023(Updated: )
** DISPUTED ** An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Systemd Project Systemd | =253 | |
=253 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31439 is a vulnerability discovered in systemd 253 that allows an attacker to modify the contents of past events in a sealed log file without detection.
The severity of CVE-2023-31439 is medium, with a severity score of 5.3.
Yes, an attacker can modify the contents of past events in a sealed log file in systemd 253 without detection.
At the moment, there are no known fixes or patches available for CVE-2023-31439. It is advised to follow the recommendations provided by the vendor or project maintainers.
Yes, additional information about CVE-2023-31439 can be found in the references provided: [link 1](https://github.com/kastel-security/Journald), [link 2](https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf), [link 3](https://github.com/systemd/systemd/releases).