Описание
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 233-8ubuntu2 |
| esm-infra-legacy/trusty | not-affected | 204-5ubuntu20.24 |
| esm-infra/xenial | released | 229-4ubuntu19 |
| precise/esm | DNE | |
| trusty | not-affected | 204-5ubuntu20.24 |
| trusty/esm | not-affected | 204-5ubuntu20.24 |
| upstream | needed | |
| vivid/ubuntu-core | not-affected | 219-7ubuntu6 |
| xenial | released | 229-4ubuntu19 |
| yakkety | released | 231-9ubuntu5 |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
In systemd through 233, certain sizes passed to dns_packet_new in syst ...
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
EPSS
5 Medium
CVSS2
7.5 High
CVSS3