CVE-2017-9217: Null Pointer Dereference
Published May 24, 2017
·Updated
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.
Affected Software
1 affected component
Systemd Project Systemd<=233
Remediation
Patch Available
Event History
May 24, 2017
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9217?
CVE-2017-9217 is classified as a medium severity vulnerability affecting systemd-resolved.
2
How does CVE-2017-9217 affect affected software?
CVE-2017-9217 allows remote attackers to exploit the vulnerability to crash the systemd-resolved daemon.
3
How do I fix CVE-2017-9217?
To mitigate CVE-2017-9217, upgrade systemd to a version higher than 233.
4
What versions of systemd are affected by CVE-2017-9217?
CVE-2017-9217 affects systemd versions up to and including 233.
5
Can CVE-2017-9217 be exploited remotely?
Yes, CVE-2017-9217 can be exploited by remote attackers through crafted DNS responses.