CVE-2011-4869: High severity unbound vulnerability
validator/valnsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4869?
CVE-2011-4869 has a severity rating that indicates it can lead to a denial of service condition.
How do I fix CVE-2011-4869?
To fix CVE-2011-4869, you should upgrade Unbound to version 1.4.13p2 or later.
What versions of Unbound are affected by CVE-2011-4869?
CVE-2011-4869 affects Unbound versions prior to 1.4.13p2, including several earlier versions.
What is the impact of CVE-2011-4869?
The impact of CVE-2011-4869 is that it allows remote DNS servers to crash the daemon via malformed DNS responses.
Is CVE-2011-4869 related to other vulnerabilities?
Yes, CVE-2011-4869 is specifically mentioned as a different vulnerability from CVE-2011-4528.