~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2017-9217

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-9217
2
 
PublicDate: 2017-05-24
3
 
References: 
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9217
5
 
 https://github.com/systemd/systemd/pull/5998
6
 
 https://github.com/systemd/systemd/pull/6020
7
 
Description: 
8
 
 systemd-resolved through 233 allows remote attackers to cause a denial of
9
 
 service (daemon crash) via a crafted DNS response with an empty question
10
 
 section.
11
 
Ubuntu-Description: 
12
 
Notes: 
13
 
 tyhicks> I believe that this was introduced in v223 by
14
 
  https://github.com/systemd/systemd/commit/29815b6c608b836cada5e349d06a96b63eaa65f3
15
 
 tyhicks> Lennart pointed out in the pull request that systemd-resolved is
16
 
  respawned after crashing. Therefore, I've rated this as a low priority.
17
 
 tyhicks> systemd-resolved became the default DNS resolver in Zesty and it is
18
 
  enabled in Yakkety
19
 
 tyhicks> systemd-resolved is not used by default in Xenial. It is spawned if a
20
 
  user execs the systemd-resolve utility but that shouldn't impact the system.
21
 
Bugs: 
22
 
 https://launchpad.net/bugs/1621396
23
 
Priority: low
24
 
Discovered-by:
25
 
Assigned-to: 
26
 
 
27
 
Patches_systemd:
28
 
 upstream: https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be
29
 
upstream_systemd: needed
30
 
precise/esm_systemd: DNE
31
 
trusty_systemd: not-affected (204-5ubuntu20.24)
32
 
vivid/stable-phone-overlay_systemd: not-affected (219-7ubuntu6vividtouch1)
33
 
vivid/ubuntu-core_systemd: not-affected (219-7ubuntu6)
34
 
Priority_systemd_xenial: negligible
35
 
xenial_systemd: released (229-4ubuntu19)
36
 
yakkety_systemd: ignored (reached end-of-life)
37
 
zesty_systemd: released (232-21ubuntu4)
38
 
devel_systemd: released (233-6ubuntu3)