CVE-2023-31439: Medium severity Systemd Project Systemd vulnerability
DISPUTED An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-31439?
CVE-2023-31439 is a vulnerability discovered in systemd 253 that allows an attacker to modify the contents of past events in a sealed log file without detection.
What is the severity of CVE-2023-31439?
The severity of CVE-2023-31439 is medium, with a severity score of 5.3.
Can an attacker modify log files without detection in systemd 253?
Yes, an attacker can modify the contents of past events in a sealed log file in systemd 253 without detection.
Are there any known fixes or patches for CVE-2023-31439?
At the moment, there are no known fixes or patches available for CVE-2023-31439. It is advised to follow the recommendations provided by the vendor or project maintainers.
Is there additional information available about CVE-2023-31439?
Yes, additional information about CVE-2023-31439 can be found in the references provided: [link 1](https://github.com/kastel-security/Journald), [link 2](https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf), [link 3](https://github.com/systemd/systemd/releases).