CVE-2011-4869Unbound vulnerability

6 documents6 sources
Severity
7.8HIGHNVD
CNA5.0OSV5.0
EPSS
2.1%
top 15.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20
Latest updateMay 17

Description

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

Debiannlnetlabs/unbound< 1.4.14-1+3
NVDunbound/unbound1.4.12+38

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6xqx-v8qv-h8xm: validator/val_nsec32022-05-17
OSV
CVE-2011-4869: validator/val_nsec32011-12-20
CVEList
CVE-2011-4869: validator/val_nsec32011-12-20

📋Vendor Advisories

1
Debian
CVE-2011-4869: unbound - validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof...2011

💬Community

1
Bugzilla
CVE-2011-4528 CVE-2011-4869 unbound 1.4.13 DNS Server multiple crashes2011-12-19
CVE-2011-4869 — Unbound vulnerability | cvebase