5
CVSSv2

CVE-2009-4008

Published: 02/06/2011 Updated: 14/06/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Unbound prior to 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote malicious users to cause a denial of service (DNSSEC outage) via a crafted query.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nlnetlabs unbound 1.0.1

nlnetlabs unbound 1.0.2

nlnetlabs unbound 0.8

nlnetlabs unbound 0.7.2

nlnetlabs unbound 1.4.1

nlnetlabs unbound 1.4.0

nlnetlabs unbound 1.3.4

nlnetlabs unbound 1.4.2

nlnetlabs unbound 1.2.0

nlnetlabs unbound 1.0.0

nlnetlabs unbound 0.7.1

nlnetlabs unbound 1.1.1

nlnetlabs unbound 0.6

nlnetlabs unbound 0.4

nlnetlabs unbound 1.3.0

nlnetlabs unbound 1.3.1

nlnetlabs unbound 1.3.2

nlnetlabs unbound 1.3.3

nlnetlabs unbound 0.10

nlnetlabs unbound 0.09

nlnetlabs unbound 0.2

nlnetlabs unbound 0.1

nlnetlabs unbound 1.1.0

nlnetlabs unbound 1.2.1

nlnetlabs unbound 0.7

nlnetlabs unbound 0.11

nlnetlabs unbound 0.0

nlnetlabs unbound 0.5

nlnetlabs unbound 0.3

nlnetlabs unbound

Vendor Advisories

It was discovered that Unbound, a caching DNS resolver, ceases to provide answers for zones signed using DNSSEC after it has processed a crafted query (CVE-2009-4008) In addition, this update improves the level of DNSSEC support in the lenny version of Unbound so that it is possible for system administrators to configure the trust anchor for the r ...