Wind River Support Network

HomeDefectsLIN8-6985
Fixed

LIN8-6985 : Security Advisory - systemd - CVE-2017-9445

Created: Jun 29, 2017    Updated: May 29, 2018
Resolved Date: Apr 18, 2018
Found In Version: 8.0.0.18
Fix Version: 8.0.0.19
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.

https://nvd.nist.gov/vuln/detail/CVE-2017-9445

Other Downloads


CVEs


Live chat
Online