NA

CVE-2023-7008

Published: 23/12/2023 Updated: 22/05/2024
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

systemd_project systemd 25

Vendor Advisories

Debian Bug report logs - #1059278 systemd: CVE-2023-7008 Package: src:systemd; Maintainer for src:systemd is Debian systemd Maintainers <pkg-systemd-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 12:12:02 UTC Severity: minor Tags: security, upstream Foun ...