systemd-resolved Remote DNS Cache Poisoning Vulnerability
BID:71062
Info
systemd-resolved Remote DNS Cache Poisoning Vulnerability
| Bugtraq ID: | 71062 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2014 12:00AM |
| Updated: | Nov 12 2014 12:00AM |
| Credit: | Santa L. Helper |
| Vulnerable: |
systemd-resolved systemd-resolved 0 |
| Not Vulnerable: | |
Discussion
systemd-resolved Remote DNS Cache Poisoning Vulnerability
systemd-resolved is prone to a remote DNS cache-poisoning vulnerability.
An attacker can exploit this issue to divert data from a legitimate site to an attacker-specified site.
Successfully exploiting this issue will allow attackers to poison the DNS cache and steal the victimâ??s cookies or perform site-impersonation; other attacks are also possible.
systemd-resolved is prone to a remote DNS cache-poisoning vulnerability.
An attacker can exploit this issue to divert data from a legitimate site to an attacker-specified site.
Successfully exploiting this issue will allow attackers to poison the DNS cache and steal the victimâ??s cookies or perform site-impersonation; other attacks are also possible.
Exploit / POC
systemd-resolved Remote DNS Cache Poisoning Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
systemd-resolved Remote DNS Cache Poisoning Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
systemd-resolved Remote DNS Cache Poisoning Vulnerability
References:
References: