systemd 239 through 245 accepts any certificate signed by a...
Vulnerability Description
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-21029
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/systemd/systemd/issues/9397
- https://blog.cloudflare.com/dns-encryption-explained/
- https://github.com/systemd/systemd/blob/v243/src/resolve/resolved-dnstls-gnutls.c#L62-L63
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NLJVOJMB6ANDILRLDZK26YGLYBEPHKY/
- https://security.netapp.com/advisory/ntap-20191122-0002/
- https://github.com/systemd/systemd/pull/13870
- https://github.com/systemd/systemd/blob/v243/man/resolved.conf.xml#L196-L207
- https://github.com/systemd/systemd/blob/v239/man/resolved.conf.xml#L199-L207
- https://tools.ietf.org/html/rfc7858#section-4.1
More from systemd project
View All →Affected Vendor
systemd project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.