Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ralph Dolmans

Pesquisador deNLNetLabs
#17807de 53,639
15.1CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2019-16733
9.8
2019-01-23
Powerdns · Powerdns Recursor · CVE-2019-3807
**Name of the Vulnerable Software and Affected Versions** PowerDNS Recursor versions 4.1.x through 4.1.8 **Description** An issue has been found where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation. **Recommendations** For PowerDNS Recursor versions 4.1.x through 4.1.8, update to version 4.1.9 or later to resolve the issue.
PT-2018-5765
5.3
2018-01-22
Nlnet · Unbound · CVE-2017-15105
Name of the Vulnerable Software and Affected Versions: unbound versions prior to 1.6.8 Description: A flaw was found in the way unbound validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence of an existing wildcard record, or trick unbound into accepting a NODATA proof. Recommendations: For versions prior to 1.6.8, update to version 1.6.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of wildcard NSEC records until a patch is available.