mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 17:21:36 +00:00
298 lines
11 KiB
JSON
298 lines
11 KiB
JSON
{
|
|
"id": "CVE-2011-4869",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2011-12-20T11:55:08.820",
|
|
"lastModified": "2017-08-29T01:30:36.973",
|
|
"vulnStatus": "Modified",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "validator/val_nsec3.c en Unbound antes de v1.4.13p2, no realiza adecuadamente el postprocesamiento de la prueba para zonas NSEC3-signed, lo que permite a servidores DNS remotos provocar una denegaci\u00f3n de servicio (ca\u00edda del demonio) a trav\u00e9s de una respuesta con formato incorrecto que carece de registros NSEC3 esperados. Una vulnerabilidad diferente de CVE-2011-4528."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "COMPLETE",
|
|
"baseScore": 7.8
|
|
},
|
|
"baseSeverity": "HIGH",
|
|
"exploitabilityScore": 10.0,
|
|
"impactScore": 6.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-399"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "1.4.12",
|
|
"matchCriteriaId": "948A3568-4A06-4C18-BDA5-09D67496EACB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7515192E-C07E-4399-85D0-2A1BC2F9B993"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "34D6D064-EA2B-4BA9-9D30-5A92DE178608"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "55FAC8A9-EF56-407C-BF10-41F7C768E30A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E302E40E-EA2F-4021-89BB-B6B9B6B995A7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E90F2613-9484-46DC-AE00-23F5E803771B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "39CCA38F-6DFD-4506-BAE3-A587F1A1D017"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "10DD7299-6C4E-46EA-BAD8-FE8B868995A7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "836ABCDF-C8DB-4485-B7AE-E03AA281DB69"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.7.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3992786F-0848-497D-8BE2-924C57FF94ED"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.7.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "AD592895-AF66-4F27-A7FE-00C4FCC06BFC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.8:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0FA67BEE-E12C-4CEA-AFF0-008B0226B4A1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.09:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FF97B8FC-4CC9-412E-A24D-6A74671EDE66"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4D0C50E1-4234-452E-B172-9A5C180899F9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:0.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F81D9F43-8435-452A-8784-63BABA66BFA4"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.0.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A2A428BA-0BA7-4BBF-AC59-C14E5CCD5DCC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.0.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0344EB60-49BD-4F42-A123-E68D92D4357C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.0.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "55620605-A826-45B6-A539-F93ACC6136F3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CCB47D47-ECBC-491F-B75D-0C59D292F030"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D19FA146-0379-4FAD-ABD1-A5F74CEBEC4F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8E4D0493-2252-4A24-9541-7ABE1D09A594"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.2.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4123BEB8-8BE3-4A63-9EA2-1CD81F673F16"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.3.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B2E809EF-3FE1-45A5-B6F5-0ADBA3DD1B54"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.3.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "43B6AF61-C55F-460B-AC6B-4736A49B9925"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.3.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B3CEC475-F5E1-4663-BBDC-E7A0E8C4072E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.3.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "96AA4EB6-096C-47C6-8363-3D5652D89E33"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.3.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "845BB2BD-4CEA-48DA-8FA4-CFB79DE03939"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C9113AD4-25B3-40ED-80DB-5A4EC21AA1F5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9640A5D9-C1B3-49F1-AFAA-6D57066A2072"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A6DC0896-75BA-4DD3-9B30-DFD531E4336E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1B2FDA5D-6F4F-4870-B229-FD48C663B8E4"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "58C6E245-8D36-43B7-B1B0-9B0B19C45EAA"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0DB6BD03-BBBF-4AD9-9076-30B423A345E0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9728B9F3-4A4C-4332-9821-D82F81C2F4C7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "27F18C3C-6E8B-46EF-8301-E3768F7AE739"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.8:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0F238D5D-2E86-4F79-84ED-1822338AF65A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.9:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E0D54E5E-BF0E-46F3-BB3A-E0FC7F5B93A7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "564EB98A-535A-4EC5-B145-127156AD6452"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:unbound:unbound:1.4.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FFFA0D04-1B5E-4F3F-811C-F46BAB760F03"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071535.html",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://unbound.nlnetlabs.nl/downloads/CVE-2011-4528.txt",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Patch",
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.debian.org/security/2011/dsa-2370",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.kb.cert.org/vuls/id/209659",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Patch",
|
|
"US Government Resource"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71868",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |