Description
validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2370-1 | unbound security update |
EUVD |
EUVD-2011-4786 | validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T00:16:34.980Z
Reserved: 2011-12-20T00:00:00.000Z
Link: CVE-2011-4869
No data.
Status : Modified
Published: 2011-12-20T11:55:08.820
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-4869
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD