A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade unbound | Feb 19, 2019 | Jan 23, 2018 |
| Freebsd | — | Upgrade unbound | Jan 20, 2018 | Jan 19, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade unboundUpgrade unbound-libs | Dec 4, 2019 | Jan 23, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade unbound-libsUpgrade unbound | Dec 18, 2019 | Jan 23, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade unbound-libsUpgrade unbound | Nov 19, 2019 | Jan 23, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 23, 2018 |
| Suse | — | Upgrade unbound-develUpgrade libunbound2Upgrade unbound-anchor | May 20, 2018 | Oct 8, 2017 |
| Ubuntu | — | Upgrade unboundUpgrade libunbound2 | Jun 13, 2018 | Oct 8, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub