CVE Vulnerabilities

CVE-2011-4528

Published: Dec 20, 2011 | Modified: Nov 06, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.

Affected Software

Name Vendor Start Version End Version
Unbound Unbound 1.3.3 1.3.3
Unbound Unbound * 1.4.13
Unbound Unbound 0.7 0.7
Unbound Unbound 0.0 0.0
Unbound Unbound 0.6 0.6
Unbound Unbound 0.4 0.4
Unbound Unbound 0.2 0.2
Unbound Unbound 1.3.1 1.3.1
Unbound Unbound 0.11 0.11
Unbound Unbound 1.3.4 1.3.4
Unbound Unbound 1.0.0 1.0.0
Unbound Unbound 1.4.7 1.4.7
Unbound Unbound 1.2.0 1.2.0
Unbound Unbound 1.3.2 1.3.2
Unbound Unbound 1.3.0 1.3.0
Unbound Unbound 1.4.4 1.4.4
Unbound Unbound 1.4.1 1.4.1
Unbound Unbound 0.1 0.1
Unbound Unbound 1.1.0 1.1.0
Unbound Unbound 1.4.6 1.4.6
Unbound Unbound 0.3 0.3
Unbound Unbound 1.4.10 1.4.10
Unbound Unbound 0.7.2 0.7.2
Unbound Unbound 1.4.8 1.4.8
Unbound Unbound 1.0.1 1.0.1
Unbound Unbound 1.0.2 1.0.2
Unbound Unbound 1.4.12 1.4.12
Unbound Unbound 1.4.14 1.4.14
Unbound Unbound 0.7.1 0.7.1
Unbound Unbound 1.2.1 1.2.1
Unbound Unbound 1.4.11 1.4.11
Unbound Unbound 0.8 0.8
Unbound Unbound 1.4.3 1.4.3
Unbound Unbound 1.4.2 1.4.2
Unbound Unbound 0.10 0.10
Unbound Unbound 1.4.0 1.4.0
Unbound Unbound 0.09 0.09
Unbound Unbound 1.4.5 1.4.5
Unbound Unbound 1.1.1 1.1.1
Unbound Unbound 1.4.9 1.4.9
Unbound Unbound 0.5 0.5

References