Unrated severityNVD Advisory· Published Jan 23, 2018· Updated Sep 16, 2024
CVE-2017-15105
CVE-2017-15105
Description
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- usn.ubuntu.com/3673-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.securityfocus.com/bid/102817mitrevdb-entryx_refsource_BID
- lists.debian.org/debian-lts-announce/2018/01/msg00039.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2019/02/msg00022.htmlmitremailing-listx_refsource_MLIST
- unbound.net/downloads/CVE-2017-15105.txtmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.