PT-2019-10455 · Systemd+1 · Systemd+1

Published

2019-10-30

·

Updated

2024-08-05

·

CVE-2018-21029

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions systemd versions 239 through 245
Description The issue concerns the acceptance of any certificate signed by a trusted certificate authority for DNS Over TLS, without sending Server Name Indication (SNI) and without hostname validation when using the GnuTLS backend. It has been disputed by the developer as not being a vulnerability, arguing that hostname validation is not relevant in this context.
Recommendations For versions 239 through 245, consider restricting the use of DNS Over TLS with the GnuTLS backend until a resolution is determined, as the developer dispute may indicate a need for further review or clarification on the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3220
ALT-PU-2021-1673
ALT-PU-2021-1950
CVE-2018-21029
OPENSUSE-SU-2024:11420-1

Affected Products

Alt Linux
Systemd