A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2023-7008 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2222261 | Issue Tracking |
| https://bugzilla.redhat.com/show_bug.cgi?id=2222672 | Issue Tracking |
| https://github.com/systemd/systemd/issues/25676 | Issue Tracking |
Configurations
Configuration 1 (hide)
| AND |
|
Information
Published : 2023-12-23 13:15
Updated : 2024-01-04 19:14
NVD link : CVE-2023-7008
Mitre link : CVE-2023-7008
JSON object : View
Products Affected
debian
- debian_linux
systemd_project
- systemd
CWE
