First published: Thu Jun 02 2011(Updated: )
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libunbound | <=1.4.3 | |
libunbound | =0.0 | |
libunbound | =0.1 | |
libunbound | =0.2 | |
libunbound | =0.3 | |
libunbound | =0.4 | |
libunbound | =0.5 | |
libunbound | =0.6 | |
libunbound | =0.7 | |
libunbound | =0.7.1 | |
libunbound | =0.7.2 | |
libunbound | =0.8 | |
libunbound | =0.09 | |
libunbound | =0.10 | |
libunbound | =0.11 | |
libunbound | =1.0.0 | |
libunbound | =1.0.1 | |
libunbound | =1.0.2 | |
libunbound | =1.1.0 | |
libunbound | =1.1.1 | |
libunbound | =1.2.0 | |
libunbound | =1.2.1 | |
libunbound | =1.3.0 | |
libunbound | =1.3.1 | |
libunbound | =1.3.2 | |
libunbound | =1.3.3 | |
libunbound | =1.3.4 | |
libunbound | =1.4.0 | |
libunbound | =1.4.1 | |
libunbound | =1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4008 is classified as a denial of service vulnerability that affects Unbound versions prior to 1.4.4.
To address CVE-2009-4008, you should upgrade Unbound to version 1.4.4 or later.
CVE-2009-4008 affects all versions of Unbound before 1.4.4, including versions as low as 0.0.
CVE-2009-4008 can be exploited by remote attackers who send crafted queries to induce a DNSSEC outage.
CVE-2009-4008 is considered critical due to its potential to disrupt DNS services.