A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2023-12-23 13:15
Updated : 2024-05-22 17:16
NVD link : CVE-2023-7008
Mitre link : CVE-2023-7008
CVE.ORG link : CVE-2023-7008
JSON object : View
Products Affected
debian
- debian_linux
systemd_project
- systemd
CWE