CVE-2018-16866 log

Source
Severity Medium
Remote No
Type Information disclosure
Description
An out-of-bounds read has been found in the journald component of systemd >= v221 and < v240, in the syslog_parse_identifier() function in journald-syslog.c. A crafted syslog message whose last character is ':' can trigger this vulnerability to leak information about the content of the memory.
Group Package Affected Fixed Severity Status Ticket
AVG-615 systemd 239.2-1 240.0-3 Medium Fixed
Date Advisory Group Package Severity Type
08 Jan 2019 ASA-201901-4 AVG-615 systemd Medium multiple issues
References
https://www.qualys.com/2019/01/09/system-down/system-down.txt
https://www.openwall.com/lists/oss-security/2019/01/09/3
https://github.com/systemd/systemd/commit/a6aadf4ae0bae185dc4c414d492a4a781c80ffe5
https://github.com/systemd/systemd/commit/8595102d3ddde6d25c282f965573a6de34ab4421