CVE ID | CVE-2017-15908 |
CVSS SCORE | 7.8, AV:N/AC:L/Au:N/C:N/I:N/A:C |
AFFECTED VENDORS |
systemd |
AFFECTED PRODUCTS |
Network Name Resolution Manager |
VULNERABILITY DETAILS |
The specific flaw exists within the handling of NSEC resource records in systemd-resolved. The issue results from the lack of proper handling of the pseudo-types in the NSEC bitmap which causes an infinite loop. An attacker can leverage this vulnerability to trigger a denial of service condition for the system users. |
ADDITIONAL DETAILS |
systemd has issued an update to correct this vulnerability. More details can be found at:
https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-15908.html |
DISCLOSURE TIMELINE |
|
CREDIT | Nelson William Gamazo Sanchez - Trend Micro |