Denial of Service Vulnerability in Unbound DNS Resolver by NLnet Labs
CVE-2014-8602

Currently unrated

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
11 December 2014

What is CVE-2014-8602?

The vulnerability in iterator.c of NLnet Labs' Unbound DNS Resolver prior to version 1.5.1 allows remote attackers to exploit the system by sending a large or infinitely recursive number of DNS referrals. This exploitation leads to significant resource consumption, causing memory and CPU exhaustion and potentially resulting in a denial of service condition.

References

EPSS Score

25% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.