CVE-2018-16866 - log back

CVE-2018-16866 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Local
Type
+ Information disclosure
Description
+ An out-of-bounds read has been found in the journald component of systemd >= v221 and < v240, in the syslog_parse_identifier() function in journald-syslog.c. A crafted syslog message whose last character is ':' can trigger this vulnerability to leak information about the content of the memory.
References
+ https://www.qualys.com/2019/01/09/system-down/system-down.txt
+ https://www.openwall.com/lists/oss-security/2019/01/09/3
+ https://github.com/systemd/systemd/commit/a6aadf4ae0bae185dc4c414d492a4a781c80ffe5
+ https://github.com/systemd/systemd/commit/8595102d3ddde6d25c282f965573a6de34ab4421
Notes