Описание
The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.
Ссылки
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.1 (включая)
cpe:2.3:a:dnssec-tools:dnssec-tools:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.0127
Низкий
5 Medium
CVSS2
Дефекты
CWE-255
Связанные уязвимости
debian
больше 18 лет назад
The DNSSEC validation library (libval) library in dnssec-tools before ...
github
больше 4 лет назад
The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.
EPSS
Процентиль: 67%
0.0127
Низкий
5 Medium
CVSS2
Дефекты
CWE-255