systemd: systemd-resolved allows unprivileged users to configure DNS
Published Sep 4, 2019
4.4
MEDIUMCVSS 3.1
EPSS 0.51%
Description
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.
Affected products
No data.
Configuration 1
- 240
Configuration 2
- 29
- 30
- 31
Configuration 3
- 4.1
- 8.0
- 8.1
- 8.2
- 8.4
- n/a
- 8.1
- 8.2
- 8.4
- 8.1
- 8.2
- 8.0
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
No data.
Red Hat Enterprise Linux 8
systemd-0:239-18.el8
Fixed · RHSA-2019:3592
Red Hat OpenShift Container Platform 4
machine-os-content-container
Fixed · RHSA-2019:3941
Red Hat Enterprise Linux 7
systemd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | systemd-0:239-18.el8 | Fixed | RHSA-2019:3592 |
| Red Hat OpenShift Container Platform 4 | machine-os-content-container | Fixed | RHSA-2019:3941 |
| Red Hat Enterprise Linux 7 | systemd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7 as the shipped systemd-resolved does not provide any privileged DBus method. This issue does affect the versions of systemd as shipped with Red Hat Enterprise Linux 8, however the systemd-resolved service is not enabled by default, so the flaw cannot be exploited unless the service was manually enabled. The flaw was rated as Moderate as it requires a local attacker and changing the DNS servers cannot compromise the system by itself, though it could be used for phishing attacks or to redirect the users to malicious websites. Moreover, on Red Hat Enterprise Linux 8 systemd-resolved needs to be manually enabled by an administrator to make the system vulnerable. OpenShift Container Platform 4 includes a vulnerable version of systemd on RHEL CoreOS nodes. However, the systemd-resolved service is removed from RHEL CoreOS instances, making this vulnerability not exploitable. This flaw is rated Low for OpenShift Container Platform 4.
Red Hat mitigation
Disable systemd-resolved service by using `sudo systemctl disable systemd-resolved`.
References (11)
- http://www.openwall.com/lists/oss-security/2019/09/03/1 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3592 vendor-advisoryx_refsource_REDHATIssue TrackingThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3941 vendor-advisoryx_refsource_REDHATIssue TrackingPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-15718 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1746057 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6654 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRE5IS24XTF5WNZGH2L7GSQJKARBOEGL/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HIKGKXZ5OEGOEYURHLJHEMFYNLEGAW5B/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2WNHRJW4XI6H5YMDG4BUFGPAXWUMUVG/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-15718
- https://www.cve.org/CVERecord?id=CVE-2019-15718
Change history (0)
No recorded changes yet.