CVE-2011-4869

Publication date 20 December 2011

Last updated 24 July 2024


Ubuntu priority

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.

Status

Package Ubuntu Release Status
unbound 11.10 oneiric
Fixed 1.4.12-1ubuntu1
11.04 natty
Fixed 1.4.9-0ubuntu1.2
10.10 maverick
Fixed 1.4.5-1ubuntu1.2
10.04 LTS lucid
Fixed 1.4.1-2ubuntu0.2
8.04 LTS hardy Not in release