Vulnerability Description
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Unbound | <= 1.4.3 |
Related Weaknesses (CWE)
References
- http://packages.debian.org/changelogs/pool/main/u/unbound/unbound_1.4.6-1/change
- http://unbound.nlnetlabs.nl/downloads/unbound-1.4.4.tar.gzPatch
- http://www.debian.org/security/2011/dsa-2243
- http://packages.debian.org/changelogs/pool/main/u/unbound/unbound_1.4.6-1/change
- http://unbound.nlnetlabs.nl/downloads/unbound-1.4.4.tar.gzPatch
- http://www.debian.org/security/2011/dsa-2243
FAQ
What is CVE-2009-4008?
CVE-2009-4008 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
How severe is CVE-2009-4008?
CVE-2009-4008 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4008?
Check the references section above for vendor advisories and patch information. Affected products include: Nlnetlabs Unbound.