CVE-2009-3602

Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.0:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.2:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.3:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.4:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.5:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.6:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.7:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.8:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.09:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.10:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:0.11:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:unbound:1.3.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:07

Type Values Removed Values Added
References () http://osvdb.org/58836 - () http://osvdb.org/58836 -
References () http://secunia.com/advisories/36996 - Vendor Advisory () http://secunia.com/advisories/36996 - Vendor Advisory
References () http://secunia.com/advisories/37913 - () http://secunia.com/advisories/37913 -
References () http://unbound.net/pipermail/unbound-users/2009-October/000852.html - Vendor Advisory () http://unbound.net/pipermail/unbound-users/2009-October/000852.html - Vendor Advisory
References () http://www.debian.org/security/2009/dsa-1963 - () http://www.debian.org/security/2009/dsa-1963 -
References () http://www.openwall.com/lists/oss-security/2009/10/09/2 - () http://www.openwall.com/lists/oss-security/2009/10/09/2 -
References () http://www.openwall.com/lists/oss-security/2009/10/09/3 - () http://www.openwall.com/lists/oss-security/2009/10/09/3 -
References () http://www.vupen.com/english/advisories/2009/2875 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/2875 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/53729 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/53729 -

Information

Published : 2009-10-13 10:30

Updated : 2024-11-21 01:07


NVD link : CVE-2009-3602

Mitre link : CVE-2009-3602

CVE.ORG link : CVE-2009-3602


JSON object : View

Products Affected

nlnetlabs

  • unbound
CWE
CWE-310

Cryptographic Issues