[Bug 1725351] Re: Systemd - Remote DOS of systemd-resolve service

Launchpad Bug Tracker 1725351 at bugs.launchpad.net
Thu Oct 26 17:43:37 UTC 2017


This bug was fixed in the package systemd - 234-2ubuntu12.1

---------------
systemd (234-2ubuntu12.1) artful-security; urgency=medium

  * SECURITY UPDATE: remote DoS in resolve (LP: #1725351)
    - debian/patches/CVE-2017-15908.patch: fix loop on packets with pseudo
      dns types in src/resolve/resolved-dns-packet.c.
    - CVE-2017-15908

 -- Marc Deslauriers <marc.deslauriers at ubuntu.com>  Thu, 26 Oct 2017
07:56:42 -0400

** Changed in: systemd (Ubuntu Artful)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to systemd in Ubuntu.
https://bugs.launchpad.net/bugs/1725351

Title:
  Systemd - Remote DOS of systemd-resolve service

Status in systemd package in Ubuntu:
  In Progress
Status in systemd source package in Zesty:
  Fix Released
Status in systemd source package in Artful:
  Fix Released
Status in systemd source package in Bionic:
  In Progress

Bug description:
  Hello,

  We would like to report a vulnerability about systemd which allows to
  DOS the systemd-resolve service.

  The vulnerability is described in the attached PDF file.

  
  Sincerely, 
  Thomas IMBERT
  Sogeti ESEC R&D

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351/+subscriptions



More information about the foundations-bugs mailing list