A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
22 May 2024, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Apr 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Jan 2024, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
24 Jan 2024, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2023-12-23 13:15
Updated : 2024-05-22 17:16
NVD link : CVE-2023-7008
Mitre link : CVE-2023-7008
CVE.ORG link : CVE-2023-7008
JSON object : View
Products Affected
systemd_project
- systemd
debian
- debian_linux
CWE
