Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2012-1192

Disclosure Date: February 17, 2012 (last updated October 04, 2023)
The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
0
Attacker Value
Unknown

CVE-2011-4528

Disclosure Date: December 20, 2011 (last updated October 04, 2023)
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
0
Attacker Value
Unknown

CVE-2011-4869

Disclosure Date: December 20, 2011 (last updated October 04, 2023)
validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.
0
Attacker Value
Unknown

CVE-2009-4008

Disclosure Date: June 02, 2011 (last updated October 04, 2023)
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
0
Attacker Value
Unknown

CVE-2011-1922

Disclosure Date: May 31, 2011 (last updated October 04, 2023)
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
0