| Navigation Search | A set of systemd-journald exploits
	Thursday January 10, 2019. 04:42 PM , from LWN.net
 
Qualys has sent out a security advisory describing three stack-overrun vulnerabilities in systemd-journald. 'We developed an exploit for CVE-2018-16865 and CVE-2018-16866 that obtains a local root shell in 10 minutes on i386 and 70 minutes on amd64, on average. We will publish our exploit in the near future. To the best of our knowledge, all systemd-based Linux distributions are vulnerable, but SUSE Linux Enterprise 15, openSUSE Leap 15.0, and Fedora 28 and 29 are not exploitable because their user space is compiled with GCC's -fstack-clash-protection.' 
https://lwn.net/Articles/776404/rss
 | 25 sources Current Date 
			Oct, Fri 24 - 23:57 CEST
	
		 | 







 Read more at LWN.net
Read more at LWN.net