3.3
CVSSv3

CVE-2019-3815

Published: 28/01/2019 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A memory leak exists in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux server eus 7.6

redhat enterprise linux server aus 7.6

redhat openshift container platform 3.11

debian debian linux 8.0

Vendor Advisories

Synopsis Low: systemd security update Type/Severity Security Advisory: Low Topic An update for systemd is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...
It was discovered that systemd is vulnerable to a state injection attack when deserializing the state of a service Properties longer than LINE_MAX are not correctly parsed and an attacker may abuse this flaw in particularly configured services to inject, change, or corrupt the service state (CVE-2018-15686) An out of bounds read was discovered in ...
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux Function dispatch_message_real() in journald-serverc does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry A local attacker may use this flaw to make systemd-journald crash ...