Lucene search

K
cve[email protected]CVE-2017-15908
HistoryOct 26, 2017 - 2:29 p.m.

CVE-2017-15908

2017-10-2614:29:00
CWE-835
web.nvd.nist.gov
170
systemd
systemd-resolved
dos
vulnerability
cve-2017-15908
nsec
dns
remote dns server

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.955 High

EPSS

Percentile

99.4%

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the ‘systemd-resolved’ service and cause a DoS of the affected service.

Affected configurations

NVD
Node
systemd_projectsystemdMatch223
OR
systemd_projectsystemdMatch224
OR
systemd_projectsystemdMatch225
OR
systemd_projectsystemdMatch226
OR
systemd_projectsystemdMatch227
OR
systemd_projectsystemdMatch228
OR
systemd_projectsystemdMatch229
OR
systemd_projectsystemdMatch230
OR
systemd_projectsystemdMatch231
OR
systemd_projectsystemdMatch232
OR
systemd_projectsystemdMatch233
OR
systemd_projectsystemdMatch234
OR
systemd_projectsystemdMatch235
Node
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch16.04lts

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.955 High

EPSS

Percentile

99.4%