Debian DLA-1762-2 : systemd regression update

high Nessus Plugin ID 124282

Synopsis

The remote Debian host is missing a security update.

Description

In the recently uploaded systemd security update (215-17+deb8u12 via DLA-1762-1), a regression was discovered in the fix for CVE-2017-18078.

The observation of Debian jessie LTS users was, that after upgrading to

+deb8u12 temporary files would not have the correct ownerships and permissions anymore (instead of a file being owned by a specific user and/or group, files were being owned by root:root; setting POSIX file permissions (rwx, etc.) was also affected).

For Debian 8 'Jessie', this regression problem has been fixed in version 215-17+deb8u13.

We recommend that you upgrade your systemd packages.

NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Upgrade the affected packages.

See Also

https://lists.debian.org/debian-lts-announce/2019/04/msg00026.html

https://packages.debian.org/source/jessie/systemd

Plugin Details

Severity: High

ID: 124282

File Name: debian_DLA-1762.nasl

Version: 1.4

Type: local

Agent: unix

Published: 4/25/2019

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:libpam-systemd, p-cpe:/a:debian:debian_linux:libsystemd-journal-dev, p-cpe:/a:debian:debian_linux:libsystemd-login-dev, p-cpe:/a:debian:debian_linux:libsystemd0, p-cpe:/a:debian:debian_linux:udev-udeb, p-cpe:/a:debian:debian_linux:systemd-sysv, p-cpe:/a:debian:debian_linux:libudev1, p-cpe:/a:debian:debian_linux:libsystemd-id128-dev, p-cpe:/a:debian:debian_linux:gir1.2-gudev-1.0, p-cpe:/a:debian:debian_linux:libsystemd-login0, p-cpe:/a:debian:debian_linux:libudev-dev, p-cpe:/a:debian:debian_linux:python3-systemd, p-cpe:/a:debian:debian_linux:systemd-dbg, p-cpe:/a:debian:debian_linux:libsystemd-journal0, p-cpe:/a:debian:debian_linux:udev, p-cpe:/a:debian:debian_linux:libsystemd-daemon-dev, p-cpe:/a:debian:debian_linux:libgudev-1.0-0, p-cpe:/a:debian:debian_linux:libsystemd-daemon0, p-cpe:/a:debian:debian_linux:libgudev-1.0-dev, p-cpe:/a:debian:debian_linux:libudev1-udeb, p-cpe:/a:debian:debian_linux:libsystemd-id128-0, cpe:/o:debian:debian_linux:8.0, p-cpe:/a:debian:debian_linux:libsystemd-dev, p-cpe:/a:debian:debian_linux:systemd

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 4/26/2019

Vulnerability Publication Date: 4/26/2019