CVE-2017-9445 is an out-of-bounds write vulnerability affecting systemd-resolved in systemd versions through 233. A malicious DNS server can exploit this by sending a specially crafted TCP payload, causing systemd-resolved to allocate an undersized buffer and write arbitrary data beyond its bounds. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity leading to high availability impact. While not listed in CISA's KEV catalog and lacking public exploit code, it has garnered significant community discussion and media coverage, suggesting awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 223, <= 233CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.