CVE-2018-1049
published 2018-02-16CVE-2018-1049: In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
7.26%
93.6th percentile
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clusterlabs | pcs | >= 0 < 0.9.149-1ubuntu1.1+esm1 | 0.9.149-1ubuntu1.1+esm1 |
| clusterlabs | pcs | >= 0 < 0.10.4-3ubuntu0.1~esm1 | 0.10.4-3ubuntu0.1~esm1 |
| clusterlabs | pcs | >= 0 < 0.10.11-2ubuntu3+esm1 | 0.10.11-2ubuntu3+esm1 |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 234-1 (bookworm) | systemd 234-1 (bookworm) |
| red_hat_inc | systemd | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| systemd_project | systemd | < 234 | 234 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
| systemd_project | systemd | >= 0 < 234-1 | 234-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2018-02-05·CVSS 7.5
CVE-2017-15908 [HIGH] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
Karim Hossen & Thomas Imbert and Nelson William Gamazo Sanchez
independently discovered that systemd-resolved incorrectly handled certain
DNS responses. A remote attacker could possibly use this issue to cause
systemd to temporarily stop responding, resulting in a denial of service.
This issue only affected Ubuntu 16.04 LTS. (CVE-2017-15908)
It was discovered that systemd incorrectly handled automounted volumes. A
local attacker could possibly use this issue to cause applications to hang,
resulting in a denial of service. (CVE-2018-1049)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-1049: systemd - In systemd prior to 234 a race condition exists between .mount and .automount un...
vendor_debian·2018·CVSS 5.9
CVE-2018-1049 [MEDIUM] CVE-2018-1049: systemd - In systemd prior to 234 a race condition exists between .mount and .automount un...
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
Scope: local
bookworm: resolved (fixed in 234-1)
bullseye: resolved (fixed in 234-1)
forky: resolved (fixed in 234-1)
sid: resolved (fixed in 234-1)
trixie: resolved (fixed in 234-1)
Red Hat
systemd: automount: access to automounted volumes can lock up
vendor_redhat·2017-05-09·CVSS 5.9
CVE-2018-1049 [MEDIUM] CWE-362 systemd: automount: access to automounted volumes can lock up
systemd: automount: access to automounted volumes can lock up
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
A race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, causing denial of service.
Package: systemd (Red Hat Enterprise Linux 8) - Not affected
OSV
pcs vulnerabilities
osv·2025-07-02·CVSS 6.1
CVE-2018-1086 pcs vulnerabilities
pcs vulnerabilities
Cedric Buissart discovered that pcs did not correctly handle certain
parameters. An attacker could possibly use this issue to leak sensitive
information or elevate their privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2018-1086)
Ondrej Mular discovered that pcs did not correctly handle Unix socket
permissions. An attacker could possibly use this issue to elevate their
privileges. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2735)
It was discovered that pcs did not correctly handle PAM authentication.
An attacker could possibly use this issue to bypass authentication
mechanisms. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-1049)
It was discovered that pcs did not correctly handle the validation of
Node names. An attack
GHSA
GHSA-4pg2-ppcx-jh29: In systemd prior to 234 a race condition exists between
ghsa_unreviewed·2022-05-13
CVE-2018-1049 [MEDIUM] CWE-362 GHSA-4pg2-ppcx-jh29: In systemd prior to 234 a race condition exists between
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
OSV
CVE-2018-1049: In systemd prior to 234 a race condition exists between
osv·2018-02-16·CVSS 5.9
CVE-2018-1049 [MEDIUM] CVE-2018-1049: In systemd prior to 234 a race condition exists between
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
OSV
systemd vulnerabilities
osv·2018-02-05·CVSS 7.5
CVE-2017-15908 [HIGH] systemd vulnerabilities
systemd vulnerabilities
Karim Hossen & Thomas Imbert and Nelson William Gamazo Sanchez
independently discovered that systemd-resolved incorrectly handled certain
DNS responses. A remote attacker could possibly use this issue to cause
systemd to temporarily stop responding, resulting in a denial of service.
This issue only affected Ubuntu 16.04 LTS. (CVE-2017-15908)
It was discovered that systemd incorrectly handled automounted volumes. A
local attacker could possibly use this issue to cause applications to hang,
resulting in a denial of service. (CVE-2018-1049)
No detection rules found.
Exploit-DB
Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
exploitdb·2020-11-27·CVSS 8.8
CVE-2018-9958 [HIGH] Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
---
# Exploit Title: Foxit Reader 9.0.1.1049 - Arbitrary Code Execution
# Date: 2020-08-29
# Exploit Author: CrossWire
# Vendor Homepage: https://www.foxitsoftware.com/
# Software Link: https://www.foxitsoftware.com/downloads/latest.php?product=Foxit-Reader&platform=Windows&version=9.0.1.1049&package_type=exe&language=English
# Version: 9.0.1.1049
# Tested on: Microsoft Windows Server 2016 10.0.14393
# CVE : [2018-9958](https://nvd.nist.gov/vuln/detail/CVE-2018-9958)
#!/usr/bin/python3
'''
| PDF generator for Foxit Reader Remote Code Execution (CVE 2018-9958) |
| Written by: Kevin Dorland (CrossWire) |
| Date: 08/29/2020 |
| |
| Exploit originally discovered by Steven Seeley (mr_me) of Source Incite |
| |
| References: |
| https://www.
Exploit-DB
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
exploitdb·2018-08-27
CVE-2018-9958 Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Foxit PDF Reader Pointer Overwrite UAF',
'Description' => %q{
Foxit PDF Reader v9.0.1.1049 has a Use-After-Free vulnerability
in the Text Annotations component and the TypedArray's use
uninitialized pointers.
The vulnerabilities can be combined to leak a vtable memory address,
which can be adjusted to point to the base address of the executable.
A ROP chain can be constructed that will execute when Foxit Reader
performs the UAF.
},
'License' => MSF_LICENSE,
'Author' =>
[
'mr_me', # Use-after-free and PoC
'bit from meepwn', # Uninitialized pointer
'
Exploit-DB
Foxit Reader 9.0.1.1049 - Remote Code Execution
exploitdb·2018-06-25·CVSS 6.5
CVE-2018-9958 [MEDIUM] Foxit Reader 9.0.1.1049 - Remote Code Execution
Foxit Reader 9.0.1.1049 - Remote Code Execution
---
%PDF
1 0 obj
>
2 0 obj
> trailer >
Exploit-DB
WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
exploitdb·2018-03-30·CVSS 5.4
CVE-2018-9034 [MEDIUM] WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
---
# Exploit Title : Relevanssi Wordpress Search Plugin Reflected Cross Site Scripting (XSS)
# Date: 23-03-2018
# Exploit Author : Stefan Broeder
# Contact : https://twitter.com/stefanbroeder
# Vendor Homepage: https://www.relevanssi.com
# Software Link: https://wordpress.org/plugins/relevanssi
# Version: 4.0.4
# CVE : CVE-2018-9034
# Category : webapps
Description
Relevanssi is a WordPress plugin with more than 100.000 active installations. Version 4.0.4 (and possibly previous versions) are affected by a Reflected XSS vulnerability.
Vulnerable part of code
File: relevanssi/lib/interface.php:1055 displays unescaped value of $_GET variable 'tab'.
..
1049 if( isset( $_REQUEST[ 'tab' ] ) ) {
1050 $active_tab = $_REQUEST[
Bugzilla
CVE-2018-18016 ImageMagick: memory leak in WritePCXImage in coders/pcx.c
bugzilla·2018-10-05·CVSS 6.5
CVE-2018-18016 [MEDIUM] CVE-2018-18016 ImageMagick: memory leak in WritePCXImage in coders/pcx.c
CVE-2018-18016 ImageMagick: memory leak in WritePCXImage in coders/pcx.c
A flaw was foudn in ImageMagick 7.0.7-28. A memory leak vulnerability in WritePCXImage in coders/pcx.c which could lead to a Denial of Service attack.
References:
https://github.com/ImageMagick/ImageMagick/issues/1049
Upstream Patch:
https://github.com/ImageMagick/ImageMagick/commit/df8a62fe4938aa41a39e815937c58bc0ed21b664
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1636581]
---
Statement:
This issue affects the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For addi
Bugzilla
CVE-2018-1049 systemd: automount: access to automounted volumes can lock up [fedora-all]
bugzilla·2018-01-16·CVSS 5.9
CVE-2018-1049 [MEDIUM] CVE-2018-1049 systemd: automount: access to automounted volumes can lock up [fedora-all]
CVE-2018-1049 systemd: automount: access to automounted volumes can lock up [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
bugzilla·2018-01-15·CVSS 5.9
CVE-2018-1049 [MEDIUM] CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
In systemd prior to 234 a race exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race like this may lead to denial of service, until mount points are unmounted.
References:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1709649
https://github.com/coreos/bugs/issues/1630
http://seclists.org/oss-sec/2018/q1/80
An upstream issue:
https://github.com/systemd/systemd/pull/5916
An upstream patch:
https://github.com/systemd/systemd/commit/e7d54bf58789545a9eb0b3964233defa0b007318
Discussion:
Created systemd tracking bugs for this issue:
Affe
http://www.securitytracker.com/id/1041520https://access.redhat.com/errata/RHSA-2018:0260https://bugzilla.redhat.com/show_bug.cgi?id=1534701https://lists.debian.org/debian-lts-announce/2018/11/msg00017.htmlhttps://usn.ubuntu.com/3558-1/http://www.securitytracker.com/id/1041520https://access.redhat.com/errata/RHSA-2018:0260https://bugzilla.redhat.com/show_bug.cgi?id=1534701https://lists.debian.org/debian-lts-announce/2018/11/msg00017.htmlhttps://usn.ubuntu.com/3558-1/
2018-02-16
Published