Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Netdata
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Netdata
ID: USN-7250-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.10
Datum: Mo, 3. Februar 2025, 16:07
Referenzen: https://www.cve.org/CVERecord?id=CVE-2023-22497
https://www.cve.org/CVERecord?id=CVE-2024-34250
https://www.cve.org/CVERecord?id=CVE-2018-18836
https://www.cve.org/CVERecord?id=CVE-2018-18837
https://www.cve.org/CVERecord?id=CVE-2024-23722
https://www.cve.org/CVERecord?id=CVE-2024-34251
https://www.cve.org/CVERecord?id=CVE-2018-18838
Applikationen: Netdata

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5172755955889742692==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------0FEaM5VllndH3dp0nz3Wxdcv"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------0FEaM5VllndH3dp0nz3Wxdcv
Content-Type: multipart/mixed;
boundary="------------OUaFxBRAuYvn023pqbEAXR8j";
protected-headers="v1"
From: Bruce Cable <bruce.cable@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <f289421b-8efd-44ef-a7e2-99b199afa869@canonical.com>
Subject: [USN-7250-1] Netdata vulnerabilities

--------------OUaFxBRAuYvn023pqbEAXR8j
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-7250-1
February 03, 2025

netdata vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in netdata.

Software Description:
- netdata: real-time performance monitoring

Details:

It was discovered that Netdata incorrectly handled parsing JSON input,
which could lead to a JSON injection. An attacker could possibly use
this issue to execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18836)

It was discovered that Netdata incorrectly handled parsing HTTP headers,
which could lead to a HTTP header injection. An attacker could possibly
use this issue to cause a denial of service or leak sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18837)

It was discovered that Netdata incorrectly handled parsing URLs, which
could lead to a log injection. An attacker could possibly use this issue
to consume system resources, resulting in a denial of service. This issue
only affected Ubuntu 18.04 LTS. (CVE-2018-18838)

It was discovered Netdata improperly authenticated API keys. An attacker
could possibly use this issue to leak sensitive information or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2023-22497)

It was discovered Fluent Bit, vendored in Netdata, incorrectly handled
parsing HTTP payloads. An attacker could possibly use this issue to
disrupt logging. This issue only affected Ubuntu 24.10. (CVE-2024-23722)

It was discovered that WebAssembly Micro Runtime, vendored in Netdata,
incorrectly handled memory. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.10.
(CVE-2024-34250, CVE-2024-34251)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
  netdata-core                    1.44.3-2ubuntu0.1
  netdata-plugins-bash            1.44.3-2ubuntu0.1
  netdata-web                     1.44.3-2ubuntu0.1

Ubuntu 22.04 LTS
  netdata-core                    1.33.1-1ubuntu1+esm1
                                  Available with Ubuntu Pro
  netdata-plugins-bash            1.33.1-1ubuntu1+esm1
                                  Available with Ubuntu Pro
  netdata-web                     1.33.1-1ubuntu1+esm1
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  netdata-core                    1.19.0-3ubuntu1+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  netdata                         1.9.0+dfsg-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  netdata-data                    1.9.0+dfsg-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

After a standard system update you need to restart Netdata to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7250-1
  CVE-2018-18836, CVE-2018-18837, CVE-2018-18838, CVE-2023-22497,
  CVE-2024-23722, CVE-2024-34250, CVE-2024-34251

Package Information:
  https://launchpad.net/ubuntu/+source/netdata/1.44.3-2ubuntu0.1

--------------OUaFxBRAuYvn023pqbEAXR8j--

--------------0FEaM5VllndH3dp0nz3Wxdcv
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature.asc"

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmegYjMFAwAAAAAACgkQuGrtzot7pOeF
mgwAneCHSrFgAcq/pHfzWcjIuN8jH4V7oq08pbcC7Qt/je288hA3xwxJRi69VAtYmGvu+/bOmCFD
VJUc8aPsJ63xdTP2+uolS61kVK12okWNRilqKg9bxBOnXMuKG2gPMSzsrCJzqrCbWb1t3PN8r4ve
TmgiPJGxi9guq4ZXuf+gP9JC0z8a436ENK91+FsiDXjFLBpNtzJaNwogZc/koTQzOkwAodXvaMlx
iEjtJFKSrvQtxASmuO99s1HQC2H6i7/lY+DFUrRxHq63G9dr5/MAu4ers4jQdmc7jnZlV2a15Bgu
DPnHlmTHkmZB4uIqcGYmVY05qlu7c7HJqBq8rsWdxdkj7k/NH38dXNWTjkK29OPeriyLpHjSEm22
nKlfFiQOySBTHI51QgLj/yVp3XgVRJkx2KtEhQdYJrgdyDMJLi0gQviGA11LSpfCHelCqAObISK0
E48zUpPT8dTIBR64xzrN+i/6yyvqnIlQYgl9+ORmJQ0eXAkPmrtMmJKdRH0a
=kSaI
-----END PGP SIGNATURE-----

--------------0FEaM5VllndH3dp0nz3Wxdcv--


--===============5172755955889742692==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============5172755955889742692==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung