Search CVE reports
51 – 60 of 43490 results
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being...
1 affected package
diffutils
| Package | 20.04 LTS |
|---|---|
| diffutils | Needs evaluation |
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |