CVE-2023-31437

SOURCE - nist

Summary

An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

EPSS Score: 0.00064 (0.276)

Common Weakness Enumeration (CWE)

SOURCE - nist

Improper Validation of Integrity Check Value


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/systemddebdebian12>=252.22-1~deb12u1Not yet available
debian/systemddebdebian10>=241-7~deb10u8Not yet available
debian/systemddebdebian11>=247.3-7+deb11u4Not yet available
debian/systemddebdebian13>=255.5-1Not yet available
debian/systemddebdebianunstable>=256~rc2-3Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.3medium

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

5.3medium