systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.
References
Link | Resource |
---|---|
https://launchpad.net/bugs/1621396 | Issue Tracking Third Party Advisory |
https://github.com/systemd/systemd/pull/5998 | Issue Tracking Patch Third Party Advisory |
https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be | Issue Tracking Patch Third Party Advisory |
http://www.securityfocus.com/bid/98677 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-05-23 22:29
Updated : 2022-01-31 10:09
NVD link : CVE-2017-9217
Mitre link : CVE-2017-9217
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
systemd_project
- systemd