Unbound DNSSEC Remote Denial of Service Vulnerability
BID:48209
Info
Unbound DNSSEC Remote Denial of Service Vulnerability
| Bugtraq ID: | 48209 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-4008 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2011 12:00AM |
| Updated: | May 27 2011 12:00AM |
| Credit: | Debian |
| Vulnerable: |
Unbound Unbound 1.4.3 Unbound Unbound 1.4.2 Unbound Unbound 1.3.4 Unbound Unbound 1.3.3 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Unbound Unbound 1.4.4 |
Discussion
Unbound DNSSEC Remote Denial of Service Vulnerability
Unbound is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote to attackers to cause a DNSSEC outage, effectively denying service to legitimate users.
Versions prior to Unbound 1.4.4 are vulnerable.
Unbound is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote to attackers to cause a DNSSEC outage, effectively denying service to legitimate users.
Versions prior to Unbound 1.4.4 are vulnerable.
Exploit / POC
Unbound DNSSEC Remote Denial of Service Vulnerability
An attacker can use readily available network utilities.
An attacker can use readily available network utilities.
Solution / Fix
Unbound DNSSEC Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.