CVE-2019-15718
published 2019-09-04CVE-2019-15718: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls…
PriorityP419medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
EPSS
0.51%
40.2th percentile
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 242-7 (bookworm) | systemd 242-7 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus_s390x | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus_s390x | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
systemd vulnerability
vendor_ubuntu·2019-09-03
CVE-2019-15718 systemd vulnerability
Title: systemd vulnerability
Summary: systemd-resolved would allow unprivileged users to change DNS settings.
It was discovered that the systemd-resolved D-Bus interface did not
enforce appropriate access controls. A local unprivileged user could
exploit this to modify a system's DNS resolver settings.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
systemd: systemd-resolved allows unprivileged users to configure DNS
vendor_redhat·2019-09-03·CVSS 4.4
CVE-2019-15718 [MEDIUM] CWE-285 systemd: systemd-resolved allows unprivileged users to configure DNS
systemd: systemd-resolved allows unprivileged users to configure DNS
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.
An improper authorization flaw was discovered in systemd-resolved in the way it configures the exposed DBus interface org.freedesktop.resolve1. An unprivileged local attacker could call all DBus methods, even when marked as privileged operations. An attacker could abuse this flaw by changing the DNS, Search Domain, LLMNR,
Debian
CVE-2019-15718: systemd - In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c...
vendor_debian·2019·CVSS 4.4
CVE-2019-15718 [MEDIUM] CVE-2019-15718: systemd - In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c...
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.
Scope: local
bookworm: resolved (fixed in 242-7)
bullseye: resolved (fixed in 242-7)
forky: resolved (fixed in 242-7)
sid: resolved (fixed in 242-7)
trixie: resolved (fixed in 242-7)
GHSA
GHSA-p39j-chr3-gjhq: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util
ghsa_unreviewed·2022-05-24
CVE-2019-15718 [MEDIUM] GHSA-p39j-chr3-gjhq: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.
OSV
CVE-2019-15718: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util
osv·2019-09-04·CVSS 4.4
CVE-2019-15718 [MEDIUM] CVE-2019-15718: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-15718 systemd: systemd-resolved allows unprivileged users to configure DNS [fedora-all]
bugzilla·2019-09-04·CVSS 4.4
CVE-2019-15718 [MEDIUM] CVE-2019-15718 systemd: systemd-resolved allows unprivileged users to configure DNS [fedora-all]
CVE-2019-15718 systemd: systemd-resolved allows unprivileged users to configure DNS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2019-15718 systemd: systemd-resolved allows unprivileged users to configure DNS
bugzilla·2019-08-27·CVSS 4.4
CVE-2019-15718 [MEDIUM] CVE-2019-15718 systemd: systemd-resolved allows unprivileged users to configure DNS
CVE-2019-15718 systemd: systemd-resolved allows unprivileged users to configure DNS
systemd-resolved does not properly enforce any access control to its dbus methods, allowing any unprivileged user to access its API. An attacker may use this flaw to configure the DNS, the Default Route or other properties of a network link. Those operations should be performed only by an high-privileged user.
Discussion:
The DBus interface exposed by systemd-resolved provides APIs to change the DNS servers, search domains, default route, DNSSEC and other properties of a link. However everybody can access those methods, thus allowing unprivileged users to force the usage of a rogue DNS server, disable DNSSEC or change the default route address. This could be used to hijack network traffic, abuse DNS reso
http://www.openwall.com/lists/oss-security/2019/09/03/1https://access.redhat.com/errata/RHSA-2019:3592https://access.redhat.com/errata/RHSA-2019:3941https://bugzilla.redhat.com/show_bug.cgi?id=1746057https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRE5IS24XTF5WNZGH2L7GSQJKARBOEGL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIKGKXZ5OEGOEYURHLJHEMFYNLEGAW5B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2WNHRJW4XI6H5YMDG4BUFGPAXWUMUVG/http://www.openwall.com/lists/oss-security/2019/09/03/1https://access.redhat.com/errata/RHSA-2019:3592https://access.redhat.com/errata/RHSA-2019:3941https://bugzilla.redhat.com/show_bug.cgi?id=1746057https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRE5IS24XTF5WNZGH2L7GSQJKARBOEGL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIKGKXZ5OEGOEYURHLJHEMFYNLEGAW5B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2WNHRJW4XI6H5YMDG4BUFGPAXWUMUVG/
2019-09-04
Published