SB2017102705 - Ubuntu update for systemd
Published: October 27, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2017-15908)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The vulnerability exists in systemd due to an infinite loop in the dns_packet_read_type_window() function in the 'systemd-resolved' service. A remote attacker can return specially crafted DNS NSEC resource record data to the connected target client system, trigger an infinite loop and cause the target systemd-resolve service to fail to respond.
Successful exploitation of the vulnerability results in denial of service.
Remediation
Install update from vendor's website.