3 results (0.003 seconds)

CVSS: 6.4EPSS: 0%CPEs: 37EXPL: 0

17 Feb 2012 — The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack. El resolver en Unbound anterior a v1.4.11 sobrescribe los nombres de caché del servidor y los valores TTL en los registros NS durante la tramitación de una respuesta a una consulta de registro A, permitiendo a atacantes remotos prov... • https://www.isc.org/files/imce/ghostdomain_camera.pdf •

CVSS: 7.5EPSS: 1%CPEs: 41EXPL: 0

20 Dec 2011 — Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response. Unbound antes de v1.4.13p2 intenta liberar memoria sin asignar durante el procesado de registros CNAME duplicados, lo que permite a servidores DNS remotos provocar una denegación de servicio (caída del demonio) a través de una respuesta modificada. Multiple Denial of Service vulnerabiliti... • http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html • CWE-399: Resource Management Errors •

CVSS: 7.8EPSS: 1%CPEs: 39EXPL: 0

20 Dec 2011 — validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528. validator/val_nsec3.c en Unbound antes de v1.4.13p2, no realiza adecuadamente el postprocesamiento de la prueba para zonas NSEC3-signed, lo que permite a servidores DNS remotos provocar una denegación de servicio (... • http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html • CWE-399: Resource Management Errors •