CVE Vulnerabilities

CVE-2012-1192

Published: Feb 17, 2012 | Modified: Feb 20, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.

Affected Software

Name Vendor Start Version End Version
Unbound Unbound * 1.4.10 (including)
Unbound Unbound 0.0 (including) 0.0 (including)
Unbound Unbound 0.1 (including) 0.1 (including)
Unbound Unbound 0.2 (including) 0.2 (including)
Unbound Unbound 0.3 (including) 0.3 (including)
Unbound Unbound 0.4 (including) 0.4 (including)
Unbound Unbound 0.5 (including) 0.5 (including)
Unbound Unbound 0.6 (including) 0.6 (including)
Unbound Unbound 0.7 (including) 0.7 (including)
Unbound Unbound 0.7.1 (including) 0.7.1 (including)
Unbound Unbound 0.7.2 (including) 0.7.2 (including)
Unbound Unbound 0.8 (including) 0.8 (including)
Unbound Unbound 0.9 (including) 0.9 (including)
Unbound Unbound 0.10 (including) 0.10 (including)
Unbound Unbound 0.11 (including) 0.11 (including)
Unbound Unbound 1.0.0 (including) 1.0.0 (including)
Unbound Unbound 1.0.1 (including) 1.0.1 (including)
Unbound Unbound 1.0.2 (including) 1.0.2 (including)
Unbound Unbound 1.1.0 (including) 1.1.0 (including)
Unbound Unbound 1.1.1 (including) 1.1.1 (including)
Unbound Unbound 1.2.0 (including) 1.2.0 (including)
Unbound Unbound 1.2.1 (including) 1.2.1 (including)
Unbound Unbound 1.3.0 (including) 1.3.0 (including)
Unbound Unbound 1.3.1 (including) 1.3.1 (including)
Unbound Unbound 1.3.2 (including) 1.3.2 (including)
Unbound Unbound 1.3.3 (including) 1.3.3 (including)
Unbound Unbound 1.3.4 (including) 1.3.4 (including)
Unbound Unbound 1.4.0 (including) 1.4.0 (including)
Unbound Unbound 1.4.1 (including) 1.4.1 (including)
Unbound Unbound 1.4.2 (including) 1.4.2 (including)
Unbound Unbound 1.4.3 (including) 1.4.3 (including)
Unbound Unbound 1.4.4 (including) 1.4.4 (including)
Unbound Unbound 1.4.5 (including) 1.4.5 (including)
Unbound Unbound 1.4.6 (including) 1.4.6 (including)
Unbound Unbound 1.4.7 (including) 1.4.7 (including)
Unbound Unbound 1.4.8 (including) 1.4.8 (including)
Unbound Unbound 1.4.9 (including) 1.4.9 (including)
Unbound Ubuntu lucid *
Unbound Ubuntu maverick *
Unbound Ubuntu natty *
Unbound Ubuntu oneiric *
Unbound Ubuntu upstream *

References