Описание
The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.
Ссылки
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.1 (включая)
cpe:2.3:a:dnssec-tools:dnssec-tools:*:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00573
Низкий
5 Medium
CVSS2
Дефекты
CWE-255
Связанные уязвимости
debian
больше 17 лет назад
The DNSSEC validation library (libval) library in dnssec-tools before ...
github
больше 3 лет назад
The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.
EPSS
Процентиль: 68%
0.00573
Низкий
5 Medium
CVSS2
Дефекты
CWE-255