Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
unbound NSEC3记录签名 验证漏洞
Vulnerability Description
Unbound 1.3.4版本之前的版本没有验证NSEC3记录的签名,这会允许远程攻击者可以借助DNS欺骗或其他DNS相关的攻击以及特制的委派响应,造成安全委派程度降级。
CVSS Information
N/A
Vulnerability Type
N/A