{"id":"MGASA-2019-0330","summary":"Updated systemd packages fix security vulnerability","details":"Updated systemd packages fix security vulnerability:\n\nNadav Markus from Palo Alto Networks discovered that systemd-resolved\ndoes not enforce appropriate access controls on its D-Bus interface and\nallows unprivileged users to execute methods that are meant to be\navailable only to privileged users. This can be exploited by local users\nto modify the system's DNS resolver settings (CVE-2019-15718).\n\nThis update also adds various upstream fixes for networkd, resolved,\nupdates the manpages, fixing some logging messages and adds some missing\nchecks that can potentially be used to cause crashes or malfunction.\n\nThe syscall filter list has been updated to properly support newer glibc\nand kernel features with seccomp and nspawn.\n","modified":"2026-04-16T04:43:25.269619580Z","published":"2019-11-19T21:16:53Z","upstream":["CVE-2019-15718"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0330.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25404"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2019/09/03/1"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:3592"}],"affected":[{"package":{"name":"systemd","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/systemd?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"241-8.4.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0330.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}