VYPR
Medium severity5.3NVD Advisory· Published Jan 23, 2018· Updated Jun 17, 2026

CVE-2017-15105

CVE-2017-15105

Description

A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Nlnetlabs/Unbound2 versions
    cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*range: <1.6.8
    • (no CPE)range: before 1.6.8
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • Unbound/Unboundllm-fuzzy
    Range: <1.6.8

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.