oss-sec mailing list archives

Re: CVE Request: systemd / journald created world readable journal files


From: cve-assign () mitre org
Date: Fri, 8 Apr 2016 13:33:32 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Fixed for volatile journals was done by this commit in v214:
https://github.com/systemd/systemd/commit/176f2acf8dee45fee832fd2ab07243f63783a238

committed Jun 11, 2014

Use CVE-2014-9770.


Fixed for the current persistent journal by this commit in v229:
https://github.com/systemd/systemd/commit/afae249efa4774c6676738ac5de6aeb4daf4889f

committed Nov 29, 2015

Use CVE-2015-8842.

- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJXB+sEAAoJEL54rhJi8gl5zhMP/3C4F7RnZztSDKJ2HhG1zuUb
eOEW8F9mh00jqV3DFBAhl5y+TGUdtiGobbcYzEImxvv4wy7NgiboXn+ENVZN49ci
Vlw8wPsj3xmwq7x5rq3fsykmqa+iCtI3LFV6mEu3NnzPWd+5O96T1j+5yCVCnahN
yfcBd4JxevTE46XPXk/Eb058pz6brT+gMJu0AZ0bpT5BAN5g7QuCeD1ZOpxDHxlS
rfWLaj0gZL3ws+U4wSg4FSvLTJIOmxfFmF9ka/aNOZOU2ifI+1vmkd2rfaAEQhsQ
Lrt16WGNnBemg5xpOoty5sowYF6t0oC8QKaquixAWholjoRTHBcQSdndqTTQ68S1
hTocmbMYFKXUSJYG0uy6jhyPPRfrZNKtiCVx9Nk7ctYshM3hmETDVpbTZzndBrVU
6VwxJckUYO3kpyejfBPz68r1OcW49ZJre6rM7qZNYl1/GESeYjzKXJ8LmpZZZc9Y
yFuZmp5vKRiHttBuHYWd0qMRb7QWnHPnIcJCT63rcQ44HqNAqxw5coabZ2ATjKS1
ZLuPGAuVlG+tF37obg+MC3+MJfd2XPTC0uFWIixy7jSMfKFooQx6ndwxnRK7swr2
8X7E2D4RQvc9vzPyWGGL2SiGmezU7r6iq5s2gA6D+Givc+d3E+Ey21S6eEhyKF4I
VGnOJyed8E7zg1AKTwc4
=Rjwg
-----END PGP SIGNATURE-----


Current thread: