Systemd resolved dns_packet_read_type_window Infinite Loop (CVE-2017-15908)

A denial-of-service vulnerability exists in the dns_packet_read_type_window function of systemdresolved component in the systemd project. This vulnerability is due to the incorrectly parsing of NSEC records in a DNS response. A malicious DNS server could exploit this vulnerability by sending a crafted DNS response.

from Check Point Update Services Advisories http://ift.tt/2Dg7VCN

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...