Unrated severityNVD Advisory· Published Oct 13, 2009· Updated Apr 23, 2026
CVE-2009-3602
CVE-2009-3602
Description
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Affected products
25cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*range: <=1.3.3
- cpe:2.3:a:nlnetlabs:unbound:0.0:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.09:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.1:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.10:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.11:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.2:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.3:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.4:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:nlnetlabs:unbound:1.3.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/36996nvdVendor Advisory
- unbound.net/pipermail/unbound-users/2009-October/000852.htmlnvdVendor Advisory
- www.vupen.com/english/advisories/2009/2875nvdVendor Advisory
- osvdb.org/58836nvd
- secunia.com/advisories/37913nvd
- www.debian.org/security/2009/dsa-1963nvd
- www.openwall.com/lists/oss-security/2009/10/09/2nvd
- www.openwall.com/lists/oss-security/2009/10/09/3nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53729nvd
News mentions
0No linked articles in our index yet.