CVE-2009-4008Unbound vulnerability

CWE-3995 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 50.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 2
Latest updateMay 2

Description

Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiannlnetlabs/unbound< 1.4.4-1+3
NVDnlnetlabs/unbound1.4.3+29

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cjjv-pc59-mghf: Unbound before 12022-05-02
OSV
CVE-2009-4008: Unbound before 12011-06-02
CVEList
CVE-2009-4008: Unbound before 12011-06-02

📋Vendor Advisories

1
Debian
CVE-2009-4008: unbound - Unbound before 1.4.4 does not send responses for signed zones after mishandling ...2009
CVE-2009-4008 — Nlnetlabs Unbound vulnerability | cvebase