A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unbound | Nlnetlabs | * | 1.6.8 (excluding) |
Unbound | Ubuntu | artful | * |
Unbound | Ubuntu | bionic | * |
Unbound | Ubuntu | trusty | * |
Unbound | Ubuntu | upstream | * |
Unbound | Ubuntu | xenial | * |