7.8
CVSSv2

CVE-2011-4869

Published: 20/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

validator/val_nsec3.c in Unbound prior to 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.

Vulnerable Product Search on Vulmon Subscribe to Product

unbound unbound 1.4.11

unbound unbound 1.4.3

unbound unbound 1.4.2

unbound unbound 1.3.1

unbound unbound 1.3.0

unbound unbound 1.0.0

unbound unbound 0.11

unbound unbound 0.10

unbound unbound 0.5

unbound unbound 0.4

unbound unbound 1.4.10

unbound unbound 1.4.9

unbound unbound 1.4.8

unbound unbound 1.4.1

unbound unbound 1.4.0

unbound unbound 1.2.1

unbound unbound 1.2.0

unbound unbound 0.09

unbound unbound 0.8

unbound unbound 0.3

unbound unbound 0.2

unbound unbound 1.4.7

unbound unbound 1.4.6

unbound unbound 1.3.4

unbound unbound

unbound unbound 1.1.1

unbound unbound 1.1.0

unbound unbound 0.7.2

unbound unbound 0.7.1

unbound unbound 0.1

unbound unbound 0.0

unbound unbound 1.4.5

unbound unbound 1.4.4

unbound unbound 1.3.3

unbound unbound 1.3.2

unbound unbound 1.0.2

unbound unbound 1.0.1

unbound unbound 0.7

unbound unbound 0.6

Vendor Advisories

It was discovered that Unbound, a recursive DNS resolver, would crash when processing certain malformed DNS responses from authoritative DNS servers, leading to denial of service CVE-2011-4528 Unbound attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone CVE-2011-4869 Unbound does not properly proce ...