Insufficient Control of Network Message Volume in Unbound by NLnet Labs
CVE-2020-12662
7.5HIGH
What is CVE-2020-12662?
A vulnerability exists in Unbound prior to version 1.10.1 that allows attackers to exploit insufficient control over network message volume. This can lead to NXNSAttack scenarios wherein random subdomains in the NSDNAME field of NS records trigger excessive DNS requests, potentially overwhelming the targeted DNS server and leading to denial of service. Organizations using affected versions should upgrade to mitigate this issue.
