Описание
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2009-3602
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53729
- http://osvdb.org/58836
- http://secunia.com/advisories/36996
- http://secunia.com/advisories/37913
- http://unbound.net/pipermail/unbound-users/2009-October/000852.html
- http://www.debian.org/security/2009/dsa-1963
- http://www.openwall.com/lists/oss-security/2009/10/09/2
- http://www.openwall.com/lists/oss-security/2009/10/09/3
- http://www.vupen.com/english/advisories/2009/2875
EPSS
CVE ID
Связанные уязвимости
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Unbound before 1.3.4 does not properly verify signatures for NSEC3 rec ...
EPSS