• CVE-2023-50868

发布时间: 2024年4月26日

修改时间: 2024年4月26日

概要

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

CVSS v3 指标

NVD openEuler
CVSS评分 7.5
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3486 systemd security update 2024年4月26日

影响产品

产品 状态
KY3.4-4A systemd Fixed
KY3.4-5A systemd Fixed
KY3.5.1 systemd Fixed
KY3.5.2 systemd Fixed