Bug#1059278: systemd: CVE-2023-7008

2023-12-23 Thread Jan Erik Petersen
Hi, I'm the reporter of the bug at https://github.com/systemd/systemd/issues/25676. I'm sorry that I have to add to the bug at this time. The commit[0] that was determined to have introduced this vulnerability is incorrect. Looking at the relevant diff[1] the commit merely introduced the

Bug#1059278: systemd: CVE-2023-7008

2023-12-22 Thread Luca Boccassi
Control: tags -1 minor On Fri, 22 Dec 2023 13:09:50 +0100 =?UTF-8?Q?Moritz_M=C3=BChlenhoff?= wrote: > Source: systemd > X-Debbugs-CC: t...@security.debian.org > Severity: important > Tags: security > > Hi, > > The following vulnerability was published for systemd. > > CVE-2023-7008[0]: >

Bug#1059278: systemd: CVE-2023-7008

2023-12-22 Thread Moritz Mühlenhoff
Source: systemd X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for systemd. CVE-2023-7008[0]: Unsigned name response in signed zone is not refused when DNSSEC=yes https://bugzilla.redhat.com/show_bug.cgi?id=672