A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
2023-12-23T13:15:07.573
2024-11-22T12:15:17.590
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | systemd_project | systemd | 25 | Yes |
Operating System | debian | debian_linux | 8.0 | No |
Operating System | debian | debian_linux | 9.0 | No |