~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2011-4869

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2011-4869
2
 
PublicDate: 2011-12-20
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4869
5
 
 http://www.kb.cert.org/vuls/id/209659
6
 
 http://unbound.nlnetlabs.nl/downloads/CVE-2011-4528.txt
7
 
Description:
8
 
 validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform
9
 
 proof processing for NSEC3-signed zones, which allows remote DNS servers to
10
 
 cause a denial of service (daemon crash) via a malformed response that
11
 
 lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
Bugs:
15
 
Priority: medium
16
 
Discovered-by:
17
 
Assigned-to:
18
 
 
19
 
Patches_unbound:
20
 
upstream_unbound: not-affected (1.4.14-1)
21
 
hardy_unbound: DNE
22
 
lucid_unbound: released (1.4.1-2ubuntu0.2)
23
 
maverick_unbound: released (1.4.5-1ubuntu1.2)
24
 
natty_unbound: released (1.4.9-0ubuntu1.2)
25
 
oneiric_unbound: released (1.4.12-1ubuntu1)
26
 
devel_unbound: not-affected (1.4.14-2)