LWN.net Logo

unbound: denial of service

Package(s):unbound CVE #(s):CVE-2011-4528 CVE-2011-4869
Created:December 23, 2011 Updated:January 4, 2012
Description: From the Debian advisory:

It was discovered that Unbound, a recursive DNS resolver, would crash when processing certain malformed DNS responses from authoritative DNS servers, leading to denial of service.

CVE-2011-4528: Unbound attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone. CVE-2011-4869: Unbound does not properly process malformed responses which lack expected NSEC3 records.

Alerts:
Debian DSA-2370-1 2011-12-22
Fedora FEDORA-2011-17282 2011-12-22
Fedora FEDORA-2011-17337 2011-12-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds