Buffer Overflow in systemd-resolved Affects systemd by Red Hat
CVE-2017-9445
7.5HIGH
What is CVE-2017-9445?
A vulnerability in systemd, specifically in systemd-resolved prior to version 233, allows for a buffer overflow. This occurs when sizes transmitted to the dns_packet_new function can lead to the allocation of a buffer that is inadequate. An attacker can exploit this by sending a specially crafted TCP payload from a malicious DNS server, effectively causing systemd-resolved to allocate insufficient memory. This misallocation can result in arbitrary data being written beyond the bounds of the allocated buffer, leading to severe system integrity and security implications.
