Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2018-16866
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.001
EPSS Ranking
24.3%
CVSS Severity
CVSS v3 Score
4.3
CVSS v2 Score
2.1
References
http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
http://seclists.org/fulldisclosure/2019/May/21
http://www.openwall.com/lists/oss-security/2019/05/10/4
http://www.securityfocus.com/bid/106527
https://access.redhat.com/errata/RHSA-2019:2091
https://access.redhat.com/errata/RHSA-2019:3222
https://access.redhat.com/errata/RHSA-2020:0593
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866
https://seclists.org/bugtraq/2019/May/25
https://security.gentoo.org/glsa/201903-07
https://security.netapp.com/advisory/ntap-20190117-0001/
https://usn.ubuntu.com/3855-1/
https://www.debian.org/security/2019/dsa-4367
https://www.qualys.com/2019/01/09/system-down/system-down.txt
http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
http://seclists.org/fulldisclosure/2019/May/21
http://www.openwall.com/lists/oss-security/2019/05/10/4
http://www.securityfocus.com/bid/106527
https://access.redhat.com/errata/RHSA-2019:2091
https://access.redhat.com/errata/RHSA-2019:3222
https://access.redhat.com/errata/RHSA-2020:0593
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866
https://seclists.org/bugtraq/2019/May/25
https://security.gentoo.org/glsa/201903-07
https://security.netapp.com/advisory/ntap-20190117-0001/
https://usn.ubuntu.com/3855-1/
https://www.debian.org/security/2019/dsa-4367
https://www.qualys.com/2019/01/09/system-down/system-down.txt
Products affected by CVE-2018-16866
Netapp
»
Active Iq Performance Analytics Services
»
Version:
N/A
cpe:2.3:a:netapp:active_iq_performance_analytics_services:-
Netapp
»
Element Software
»
Version:
N/A
cpe:2.3:a:netapp:element_software:-
Systemd Project
»
Systemd
»
Version:
221
cpe:2.3:a:systemd_project:systemd:221
Systemd Project
»
Systemd
»
Version:
222
cpe:2.3:a:systemd_project:systemd:222
Systemd Project
»
Systemd
»
Version:
223
cpe:2.3:a:systemd_project:systemd:223
Systemd Project
»
Systemd
»
Version:
224
cpe:2.3:a:systemd_project:systemd:224
Systemd Project
»
Systemd
»
Version:
225
cpe:2.3:a:systemd_project:systemd:225
Systemd Project
»
Systemd
»
Version:
226
cpe:2.3:a:systemd_project:systemd:226
Systemd Project
»
Systemd
»
Version:
227
cpe:2.3:a:systemd_project:systemd:227
Systemd Project
»
Systemd
»
Version:
228
cpe:2.3:a:systemd_project:systemd:228
Systemd Project
»
Systemd
»
Version:
229
cpe:2.3:a:systemd_project:systemd:229
Systemd Project
»
Systemd
»
Version:
230
cpe:2.3:a:systemd_project:systemd:230
Systemd Project
»
Systemd
»
Version:
231
cpe:2.3:a:systemd_project:systemd:231
Systemd Project
»
Systemd
»
Version:
232
cpe:2.3:a:systemd_project:systemd:232
Systemd Project
»
Systemd
»
Version:
233
cpe:2.3:a:systemd_project:systemd:233
Systemd Project
»
Systemd
»
Version:
234
cpe:2.3:a:systemd_project:systemd:234
Systemd Project
»
Systemd
»
Version:
235
cpe:2.3:a:systemd_project:systemd:235
Systemd Project
»
Systemd
»
Version:
236
cpe:2.3:a:systemd_project:systemd:236
Systemd Project
»
Systemd
»
Version:
237
cpe:2.3:a:systemd_project:systemd:237
Systemd Project
»
Systemd
»
Version:
238
cpe:2.3:a:systemd_project:systemd:238
Systemd Project
»
Systemd
»
Version:
239
cpe:2.3:a:systemd_project:systemd:239
Canonical
»
Ubuntu Linux
»
Version:
16.04
cpe:2.3:o:canonical:ubuntu_linux:16.04
Canonical
»
Ubuntu Linux
»
Version:
18.04
cpe:2.3:o:canonical:ubuntu_linux:18.04
Canonical
»
Ubuntu Linux
»
Version:
18.10
cpe:2.3:o:canonical:ubuntu_linux:18.10
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Redhat
»
Enterprise Linux
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux:7.6
Redhat
»
Enterprise Linux Compute Node Eus
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_compute_node_eus:7.6
Redhat
»
Enterprise Linux Desktop
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
Redhat
»
Enterprise Linux For Ibm Z Systems (Structure A)
»
Version:
7_s390x
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_(structure_a):7_s390x
Redhat
»
Enterprise Linux For Ibm Z Systems Eus
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.6
Redhat
»
Enterprise Linux For Power Big Endian
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0
Redhat
»
Enterprise Linux For Power Big Endian Eus
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.6
Redhat
»
Enterprise Linux For Power Little Endian
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0
Redhat
»
Enterprise Linux For Power Little Endian Eus
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.6
Redhat
»
Enterprise Linux For Scientific Computing
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0
Redhat
»
Enterprise Linux Server
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux_server:7.0
Redhat
»
Enterprise Linux Server Aus
»
Version:
7.4
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4
Redhat
»
Enterprise Linux Server Aus
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6
Redhat
»
Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
»
Version:
7.4
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:7.4
Redhat
»
Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:7.6
Redhat
»
Enterprise Linux Server Tus
»
Version:
7.4
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4
Redhat
»
Enterprise Linux Server Tus
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6
Redhat
»
Enterprise Linux Server Update Services For Sap Solutions
»
Version:
7.4
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.4
Redhat
»
Enterprise Linux Server Update Services For Sap Solutions
»
Version:
7.6
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.6
Redhat
»
Enterprise Linux Workstation
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved