CVE-2011-4528: Medium severity unbound vulnerability
Published Dec 20, 2011
·Updated
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
Affected Software
41 affected components
Unbound Unbound<=1.4.13
Unbound Unbound=0.0
Unbound Unbound=0.1
Unbound Unbound=0.2
Unbound Unbound=0.3
Unbound Unbound=0.4
Unbound Unbound=0.5
Unbound Unbound=0.6
Unbound Unbound=0.7
Unbound Unbound=0.7.1
Unbound Unbound=0.7.2
Unbound Unbound=0.8
Unbound Unbound=0.09
Unbound Unbound=0.10
Unbound Unbound=0.11
Unbound Unbound=1.0.0
Unbound Unbound=1.0.1
Unbound Unbound=1.0.2
Unbound Unbound=1.1.0
Unbound Unbound=1.1.1
Unbound Unbound=1.2.0
Unbound Unbound=1.2.1
Unbound Unbound=1.3.0
Unbound Unbound=1.3.1
Unbound Unbound=1.3.2
Unbound Unbound=1.3.3
Unbound Unbound=1.3.4
Unbound Unbound=1.4.0
Unbound Unbound=1.4.1
Unbound Unbound=1.4.2
Unbound Unbound=1.4.3
Unbound Unbound=1.4.4
Unbound Unbound=1.4.5
Unbound Unbound=1.4.6
Unbound Unbound=1.4.7
Unbound Unbound=1.4.8
Unbound Unbound=1.4.9
Unbound Unbound=1.4.10
Unbound Unbound=1.4.11
Unbound Unbound=1.4.12
Unbound Unbound=1.4.14-rc1
Remediation
Patch Available
Patch Available
Event History
Dec 20, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4528?
CVE-2011-4528 has a medium severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2011-4528?
To fix CVE-2011-4528, upgrade to Unbound version 1.4.13p2 or later.
3
What systems are affected by CVE-2011-4528?
CVE-2011-4528 affects various versions of Unbound including all versions prior to 1.4.13p2.
4
Can CVE-2011-4528 lead to remote attacks?
Yes, CVE-2011-4528 allows remote DNS servers to exploit the vulnerability and potentially crash the daemon.
5
Is CVE-2011-4528 related to memory management issues?
Yes, CVE-2011-4528 is caused by Unbound attempting to free unallocated memory during the processing of duplicate CNAME records.