Signature Verification Flaw in Unbound DNS Resolver by NLnet Labs
CVE-2009-3602

Currently unrated

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
13 October 2009

What is CVE-2009-3602?

The Unbound DNS resolver, prior to version 1.3.4, contains a vulnerability in its handling of NSEC3 record signature verification. This weakness can be exploited by remote attackers using crafted DNS delegation responses to downgrade secure delegations through DNS spoofing or other DNS-related attacks. This flaw compromises the integrity of DNS lookups, potentially redirecting users to malicious sites.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.