HIGH · 7.8

CVE-2011-4869

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a ma...

Vulnerability Description

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
UnboundUnbound<= 1.4.12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4869?

CVE-2011-4869 is a vulnerability with a CVSS score of 7.8 (HIGH). validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a ma...

How severe is CVE-2011-4869?

CVE-2011-4869 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4869?

Check the references section above for vendor advisories and patch information. Affected products include: Unbound Unbound.