Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-31439
HistoryJun 13, 2023 - 12:00 a.m.

CVE-2023-31439

2023-06-1300:00:00
ubuntu.com
ubuntu.com
113
cve-2023-31439
integrity checking
sealed log

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

41.2%

DISPUTED An issue was discovered in systemd 253. An attacker can
modify the contents of past events in a sealed log file and then adjust the
file such that checking the integrity shows no error, despite
modifications. NOTE: the vendor reportedly sent “a reply denying that any
of the finding was a security vulnerability.”

Notes

Author Note
mdeslaur This issue was disputed by upstream systemd developers. Marking as not-affected.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

41.2%

Related for UB:CVE-2023-31439