CVE-2017-9217
high · 7.5systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.
7.5
CVSS
15.3%
EPSS (exploit prob.)
97th
EPSS percentile
2017-05-24
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-476
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| systemd_project | systemd | <= 233 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/98677
- https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be
- https://github.com/systemd/systemd/pull/5998
- https://launchpad.net/bugs/1621396
- http://www.securityfocus.com/bid/98677
- https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be
- https://github.com/systemd/systemd/pull/5998
- https://launchpad.net/bugs/1621396
- https://security.netapp.com/advisory/ntap-20241213-0003/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-9217