Heap-based buffer overflow in systemd - CVE-2013-4391
Published: October 29, 2013 / Updated: August 19, 2020
systemd
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Integer overflow in the valid_user_field function in journal/journald-native.c in systemd. A remote attacker can use a large journal data field to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2013-4391
Sources
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357
- http://cgit.freedesktop.org/systemd/systemd/commit/?id=505b6a61c22d5565e9308045c7b9bf79f7d0517e
- http://www.debian.org/security/2013/dsa-2777
- http://www.openwall.com/lists/oss-security/2013/10/01/9
- https://bugzilla.redhat.com/show_bug.cgi?id=859051
- https://security.gentoo.org/glsa/201612-34