CVE-2011-4528

Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:unbound:unbound:*:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.0:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.2:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.3:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.4:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.5:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.6:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.7:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.8:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.09:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.10:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:0.11:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.3.4:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.8:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.9:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.10:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.11:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.12:*:*:*:*:*:*:*
cpe:2.3:a:unbound:unbound:1.4.14:rc1:*:*:*:*:*:*

History

21 Nov 2024, 01:32

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071535.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071535.html -
References () http://osvdb.org/77909 - () http://osvdb.org/77909 -
References () http://secunia.com/advisories/47326 - () http://secunia.com/advisories/47326 -
References () http://unbound.nlnetlabs.nl/downloads/CVE-2011-4528.txt - Patch, Vendor Advisory () http://unbound.nlnetlabs.nl/downloads/CVE-2011-4528.txt - Patch, Vendor Advisory
References () http://www.debian.org/security/2011/dsa-2370 - () http://www.debian.org/security/2011/dsa-2370 -
References () http://www.kb.cert.org/vuls/id/209659 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/209659 - Patch, Third Party Advisory, US Government Resource

Information

Published : 2011-12-20 11:55

Updated : 2024-11-21 01:32


NVD link : CVE-2011-4528

Mitre link : CVE-2011-4528

CVE.ORG link : CVE-2011-4528


JSON object : View

Products Affected

unbound

  • unbound
CWE
CWE-399

Resource Management Errors