CVE-2018-21029
Summary
| CVE | CVE-2018-21029 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-30 22:15:00 UTC |
| Updated | 2023-11-07 02:56:00 UTC |
| Description | ** DISPUTED ** systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| systemd/resolved.conf.xml at v239 · systemd/systemd · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 31 Update: systemd-243.4-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: systemd-243.4-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2018-21029 Systemd Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| DNS Encryption Explained |
MISC |
blog.cloudflare.com |
Third Party Advisory |
| resolved: validate IP address in certificate for DNS-over-TLS (GnuTLS) by irtimmer · Pull Request #13870 · systemd/systemd · GitHub |
MISC |
github.com |
|
| RFC 7858 - Specification for DNS over Transport Layer Security (TLS) |
MISC |
tools.ietf.org |
|
| systemd/resolved.conf.xml at v243 · systemd/systemd · GitHub |
MISC |
github.com |
|
| RFE: Certificate checking for Resolveds DNS over TLS feature · Issue #9397 · systemd/systemd · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| systemd/resolved-dnstls-gnutls.c at v243 · systemd/systemd · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900013 CBL-Mariner Linux Security Update for systemd 239
- 903146 Common Base Linux Mariner (CBL-Mariner) Security Update for systemd (2696)
- 905779 Common Base Linux Mariner (CBL-Mariner) Security Update for systemd (2696-1)