First published: Thu Sep 20 2012(Updated: )
A possibility for denial of loggin service was found in the way journald functionality of systemd, a system and service manager, processed native messages when file was chosen as their origin. A local attacker could use this flaw to provide a specially-crafted file descriptor, leading the journald file read process to block, resultingin portion of subsequent native messages intended to be logged to be ignored. Issue found by Florian Weimer, Red Hat Product Security Team
Affected Software | Affected Version | How to fix |
---|---|---|
systemd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-859104 is considered to be high due to its potential to cause denial of service.
To fix REDHAT-BUG-859104, you should update the systemd package to the latest version provided by Red Hat.
Users of Red Hat's systemd that utilize journald functionality with native messages are affected by REDHAT-BUG-859104.
REDHAT-BUG-859104 enables a local attacker to create a denial of login service by manipulating a specially crafted file descriptor.
The components involved in REDHAT-BUG-859104 are the journald functionality and file descriptor processing within systemd.