VYPR

rpm package

opensuse/nsd&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/nsd&distro=openSUSE%20Tumbleweed

Vulnerabilities (8)

  • CVE-2026-12490HigJun 25, 2026
    affected < 4.14.3-1.1fixed 4.14.3-1.1

    When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over T

  • CVE-2026-12246HigJun 25, 2026
    affected < 4.14.3-1.1fixed 4.14.3-1.1

    NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

  • CVE-2026-12245HigJun 25, 2026
    affected < 4.14.3-1.1fixed 4.14.3-1.1

    NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

  • CVE-2026-12244HigJun 25, 2026
    affected < 4.14.3-1.1fixed 4.14.3-1.1

    If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because

  • CVE-2020-28935MedDec 7, 2020
    affected < 4.3.7-1.2fixed 4.3.7-1.2

    NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an exis

  • CVE-2012-2979HigNov 1, 2019
    affected < 4.3.7-1.2fixed 4.3.7-1.2

    FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.

  • CVE-2019-13207CriJul 3, 2019
    affected < 4.3.7-1.2fixed 4.3.7-1.2

    nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.

  • CVE-2016-6173HigFeb 9, 2017
    affected < 4.3.7-1.2fixed 4.3.7-1.2

    NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.