CVE-2023-7008

A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:systemd_project:systemd:25:*:*:*:*:*:*:*
OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-23 13:15

Updated : 2024-05-22 17:16


NVD link : CVE-2023-7008

Mitre link : CVE-2023-7008

CVE.ORG link : CVE-2023-7008


JSON object : View

Products Affected

debian

  • debian_linux

systemd_project

  • systemd
CWE
NVD-CWE-Other CWE-300

Channel Accessible by Non-Endpoint