You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa systemd

Sigurnosni nedostatak programskog paketa systemd

==========================================================================
Ubuntu Security Notice USN-3466-1
October 26, 2017

systemd vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 17.10
– Ubuntu 17.04

Summary:

systemd could be made to temporarily stop responding if it received
specially crafted network traffic.

Software Description:
– systemd: system and service manager

Details:

Karim Hossen & Thomas Imbert discovered that systemd-resolved incorrectly
handled certain DNS responses. A remote attacker could possibly use this
issue to cause systemd to temporarily stop responding, resulting in a
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
systemd 234-2ubuntu12.1

Ubuntu 17.04:
systemd 232-21ubuntu7.1

In general, a standard system update will make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3466-1
CVE-2017-15908

Package Information:
https://launchpad.net/ubuntu/+source/systemd/234-2ubuntu12.1
https://launchpad.net/ubuntu/+source/systemd/232-21ubuntu7.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJZ8jHnAAoJEGVp2FWnRL6TsoMQAI5AOY46M9CqJAmsvxcUswEm
9reA6xv4JQdTB/HnyG7m3Ugbox1+/kfXItQVVNcdjPt9XIMUmNPpMuIw7k62q0wX
9aO+J4OvR+uWqjuWXddvhN/j2cpI8xiiV40GPoVUUG6YMczz94TobTm02EylYMNw
fP/CoAXET5y1bmGSKMljzo0lzn0lSs70UoLgy9KaUXcBYZb9EvyNW9/SRq9Bf+hn
uC2T4TsBhFlb+IFaDPdcKMuXy1bzsL6Idx1i4NlQVSQ/4mc2z731T6LAvwnAxB8I
zgeUToWMY3rWQ93NroqjhLWazAR0H7ulpnQNeM/bHYykKE1zG4mlcZvzWctV86Bi
GZBOmWbaRd0/dzlUdaaem99HkdZOEl0hJcKu7k8f7pxHvElEIYzUOINV5t3jmGnJ
GEg9kVb73sNWqCp8VnrHebOkC9Q7Z45akMy9MwYQoe6f3aNGDjdJqyyT6wxhgOd8
U6s8E6n4WuZ9EtVb1Dey0hIHwcHv7g9EgcpCSmqwewVr1rZmohIIoUz5zU7UV0CA
uZbFin7D2xup7rMwd2tVFqy/k5E6cc60+KtvwSMa4mWNux3A4toGjH0P6cvZC19E
dBTp2Q+IK4wn0LCfC/M3NIcFsOSBZIceWUNdP/uUkqbuurXuYhxPRuhetoEFDuWq
tI83H9ovdjagsRfDde5y
=cLR9
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostaci programskog paketa wget

Otkriveni su sigurnosni nedostaci u programskom paketu wget za operacijski sustav RHEL. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog...

Close