USN-7250-1

Source
https://ubuntu.com/security/notices/USN-7250-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7250-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7250-1
Related
Published
2025-02-03T05:37:36.069465Z
Modified
2025-02-03T05:37:36.069465Z
Summary
netdata vulnerabilities
Details

It was discovered that Netdata incorrectly handled parsing JSON input, which could lead to a JSON injection. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18836)

It was discovered that Netdata incorrectly handled parsing HTTP headers, which could lead to a HTTP header injection. An attacker could possibly use this issue to cause a denial of service or leak sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18837)

It was discovered that Netdata incorrectly handled parsing URLs, which could lead to a log injection. An attacker could possibly use this issue to consume system resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18838)

It was discovered Netdata improperly authenticated API keys. An attacker could possibly use this issue to leak sensitive information or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-22497)

It was discovered Fluent Bit, vendored in Netdata, incorrectly handled parsing HTTP payloads. An attacker could possibly use this issue to disrupt logging. This issue only affected Ubuntu 24.10. (CVE-2024-23722)

It was discovered that WebAssembly Micro Runtime, vendored in Netdata, incorrectly handled memory. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.10. (CVE-2024-34250, CVE-2024-34251)

References

Affected packages

Ubuntu:Pro:18.04:LTS / netdata

Package

Name
netdata
Purl
pkg:deb/ubuntu/netdata@1.9.0+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.0+dfsg-1ubuntu0.1~esm1

Affected versions

1.*

1.7.0+dfsg-1
1.8.0+dfsg-1
1.9.0+dfsg-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "1.9.0+dfsg-1ubuntu0.1~esm1",
            "binary_name": "netdata"
        },
        {
            "binary_version": "1.9.0+dfsg-1ubuntu0.1~esm1",
            "binary_name": "netdata-data"
        },
        {
            "binary_version": "1.9.0+dfsg-1ubuntu0.1~esm1",
            "binary_name": "netdata-dbgsym"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / netdata

Package

Name
netdata
Purl
pkg:deb/ubuntu/netdata@1.19.0-3ubuntu1+esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.19.0-3ubuntu1+esm1

Affected versions

1.*

1.16.1-2
1.19.0-3ubuntu1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-apache2"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-core"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-core-dbgsym"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-plugins-bash"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-plugins-nodejs"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-plugins-python"
        },
        {
            "binary_version": "1.19.0-3ubuntu1+esm1",
            "binary_name": "netdata-web"
        }
    ]
}

Ubuntu:Pro:22.04:LTS / netdata

Package

Name
netdata
Purl
pkg:deb/ubuntu/netdata@1.33.1-1ubuntu1+esm1?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.33.1-1ubuntu1+esm1

Affected versions

1.*

1.29.3-4
1.31.0-4
1.33.1-1ubuntu1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-apache2"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-core"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-core-dbgsym"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-plugins-bash"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-plugins-nodejs"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-plugins-python"
        },
        {
            "binary_version": "1.33.1-1ubuntu1+esm1",
            "binary_name": "netdata-web"
        }
    ]
}

Ubuntu:24.10 / netdata

Package

Name
netdata
Purl
pkg:deb/ubuntu/netdata@1.44.3-2ubuntu0.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.44.3-2ubuntu0.1

Affected versions

1.*

1.43.2-1build2
1.44.3-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata"
        },
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata-apache2"
        },
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata-core"
        },
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata-core-dbgsym"
        },
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata-plugins-bash"
        },
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata-plugins-python"
        },
        {
            "binary_version": "1.44.3-2ubuntu0.1",
            "binary_name": "netdata-web"
        }
    ]
}