HIGH
systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
Published Jun 28, 2017
7.5
HIGHCVSS 3.1
EPSS 54.84%
Description
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
Affected products
No data.
- ≥ 223 · ≤ 233
No data.
Red Hat Enterprise Linux 7
systemd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | systemd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7.
Weaknesses (1)
References (8)
- http://openwall.com/lists/oss-security/2017/06/27/8 x_refsource_CONFIRMMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/99302 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038806 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-9445 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1463609 Issue Tracking
- https://launchpad.net/bugs/1695546 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2017-9445
- https://www.cve.org/CVERecord?id=CVE-2017-9445
| Link | Providers | Tags |
|---|---|---|
| http://openwall.com/lists/oss-security/2017/06/27/8 | x_refsource_CONFIRMMailing ListPatchThird Party Advisory | |
| http://www.securityfocus.com/bid/99302 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1038806 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-9445 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1463609 | Issue Tracking | |
| https://launchpad.net/bugs/1695546 | x_refsource_CONFIRMBroken Link | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-9445 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-9445 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 28, 2017
Updated Aug 5, 2024
Reserved Jun 5, 2017
Link CVE-2017-9445
CISA Vulnrichment
Updated n/a