Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15908

Опубликовано: 26 окт. 2017
Источник: debian
EPSS Низкий

Описание

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed235-3package
systemdfixed232-25+deb9u2stretchpackage
systemdnot-affectedjessiepackage
systemdnot-affectedwheezypackage

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351

  • https://github.com/systemd/systemd/pull/7184

  • Fix: https://github.com/systemd/systemd/commit/9f939335a07085aa9a9663efd1dca06ef6405d62

EPSS

Процентиль: 56%
0.00331
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

CVSS3: 7.5
redhat
больше 8 лет назад

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

CVSS3: 7.5
nvd
больше 8 лет назад

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

CVSS3: 7.5
github
больше 3 лет назад

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

suse-cvrf
около 8 лет назад

Security update for systemd

EPSS

Процентиль: 56%
0.00331
Низкий