drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Netdata
| Name: |
Mehrere Probleme in Netdata |
|
| ID: |
USN-7250-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.10 |
|
| Datum: |
Mo, 3. Februar 2025, 16:07 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2023-22497
https://www.cve.org/CVERecord?id=CVE-2024-34250
https://www.cve.org/CVERecord?id=CVE-2018-18836
https://www.cve.org/CVERecord?id=CVE-2018-18837
https://www.cve.org/CVERecord?id=CVE-2024-23722
https://www.cve.org/CVERecord?id=CVE-2024-34251
https://www.cve.org/CVERecord?id=CVE-2018-18838 |
|
| Applikationen: |
Netdata |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============5172755955889742692== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------0FEaM5VllndH3dp0nz3Wxdcv"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------0FEaM5VllndH3dp0nz3Wxdcv Content-Type: multipart/mixed; boundary="------------OUaFxBRAuYvn023pqbEAXR8j"; protected-headers="v1" From: Bruce Cable <bruce.cable@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <f289421b-8efd-44ef-a7e2-99b199afa869@canonical.com> Subject: [USN-7250-1] Netdata vulnerabilities
--------------OUaFxBRAuYvn023pqbEAXR8j Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-7250-1 February 03, 2025
netdata vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in netdata.
Software Description: - netdata: real-time performance monitoring
Details:
It was discovered that Netdata incorrectly handled parsing JSON input, which could lead to a JSON injection. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18836)
It was discovered that Netdata incorrectly handled parsing HTTP headers, which could lead to a HTTP header injection. An attacker could possibly use this issue to cause a denial of service or leak sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18837)
It was discovered that Netdata incorrectly handled parsing URLs, which could lead to a log injection. An attacker could possibly use this issue to consume system resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18838)
It was discovered Netdata improperly authenticated API keys. An attacker could possibly use this issue to leak sensitive information or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-22497)
It was discovered Fluent Bit, vendored in Netdata, incorrectly handled parsing HTTP payloads. An attacker could possibly use this issue to disrupt logging. This issue only affected Ubuntu 24.10. (CVE-2024-23722)
It was discovered that WebAssembly Micro Runtime, vendored in Netdata, incorrectly handled memory. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.10. (CVE-2024-34250, CVE-2024-34251)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10 netdata-core 1.44.3-2ubuntu0.1 netdata-plugins-bash 1.44.3-2ubuntu0.1 netdata-web 1.44.3-2ubuntu0.1
Ubuntu 22.04 LTS netdata-core 1.33.1-1ubuntu1+esm1 Available with Ubuntu Pro netdata-plugins-bash 1.33.1-1ubuntu1+esm1 Available with Ubuntu Pro netdata-web 1.33.1-1ubuntu1+esm1 Available with Ubuntu Pro
Ubuntu 20.04 LTS netdata-core 1.19.0-3ubuntu1+esm1 Available with Ubuntu Pro
Ubuntu 18.04 LTS netdata 1.9.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro netdata-data 1.9.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro
After a standard system update you need to restart Netdata to make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7250-1 CVE-2018-18836, CVE-2018-18837, CVE-2018-18838, CVE-2023-22497, CVE-2024-23722, CVE-2024-34250, CVE-2024-34251
Package Information: https://launchpad.net/ubuntu/+source/netdata/1.44.3-2ubuntu0.1
--------------OUaFxBRAuYvn023pqbEAXR8j--
--------------0FEaM5VllndH3dp0nz3Wxdcv Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmegYjMFAwAAAAAACgkQuGrtzot7pOeF mgwAneCHSrFgAcq/pHfzWcjIuN8jH4V7oq08pbcC7Qt/je288hA3xwxJRi69VAtYmGvu+/bOmCFD VJUc8aPsJ63xdTP2+uolS61kVK12okWNRilqKg9bxBOnXMuKG2gPMSzsrCJzqrCbWb1t3PN8r4ve TmgiPJGxi9guq4ZXuf+gP9JC0z8a436ENK91+FsiDXjFLBpNtzJaNwogZc/koTQzOkwAodXvaMlx iEjtJFKSrvQtxASmuO99s1HQC2H6i7/lY+DFUrRxHq63G9dr5/MAu4ers4jQdmc7jnZlV2a15Bgu DPnHlmTHkmZB4uIqcGYmVY05qlu7c7HJqBq8rsWdxdkj7k/NH38dXNWTjkK29OPeriyLpHjSEm22 nKlfFiQOySBTHI51QgLj/yVp3XgVRJkx2KtEhQdYJrgdyDMJLi0gQviGA11LSpfCHelCqAObISK0 E48zUpPT8dTIBR64xzrN+i/6yyvqnIlQYgl9+ORmJQ0eXAkPmrtMmJKdRH0a =kSaI -----END PGP SIGNATURE-----
--------------0FEaM5VllndH3dp0nz3Wxdcv--
--===============5172755955889742692== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============5172755955889742692==--
|
|
|
|