CVE-2009-4008: Medium severity unbound vulnerability
Published Jun 2, 2011
·Updated
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
Affected Software
30 affected components
nlnetlabs Unbound<=1.4.3
nlnetlabs Unbound=0.0
nlnetlabs Unbound=0.1
nlnetlabs Unbound=0.2
nlnetlabs Unbound=0.3
nlnetlabs Unbound=0.4
nlnetlabs Unbound=0.5
nlnetlabs Unbound=0.6
nlnetlabs Unbound=0.7
nlnetlabs Unbound=0.7.1
nlnetlabs Unbound=0.7.2
nlnetlabs Unbound=0.8
nlnetlabs Unbound=0.09
nlnetlabs Unbound=0.10
nlnetlabs Unbound=0.11
nlnetlabs Unbound=1.0.0
nlnetlabs Unbound=1.0.1
nlnetlabs Unbound=1.0.2
nlnetlabs Unbound=1.1.0
nlnetlabs Unbound=1.1.1
nlnetlabs Unbound=1.2.0
nlnetlabs Unbound=1.2.1
nlnetlabs Unbound=1.3.0
nlnetlabs Unbound=1.3.1
nlnetlabs Unbound=1.3.2
nlnetlabs Unbound=1.3.3
nlnetlabs Unbound=1.3.4
nlnetlabs Unbound=1.4.0
nlnetlabs Unbound=1.4.1
nlnetlabs Unbound=1.4.2
Remediation
Patch Available
Event History
Jun 2, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4008?
CVE-2009-4008 is classified as a denial of service vulnerability that affects Unbound versions prior to 1.4.4.
2
How do I fix CVE-2009-4008?
To address CVE-2009-4008, you should upgrade Unbound to version 1.4.4 or later.
3
What systems are affected by CVE-2009-4008?
CVE-2009-4008 affects all versions of Unbound before 1.4.4, including versions as low as 0.0.
4
What kind of attacks can exploit CVE-2009-4008?
CVE-2009-4008 can be exploited by remote attackers who send crafted queries to induce a DNSSEC outage.
5
Is CVE-2009-4008 a critical vulnerability?
CVE-2009-4008 is considered critical due to its potential to disrupt DNS services.