漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Novel "ghost domain names" attack by introducing subdomain delegations
Vulnerability Description
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound's delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NLnet Labs Unbound 代码问题漏洞
Vulnerability Description
NLnet Labs Unbound是NLnet Labs公司的一款开源DNS服务器。 NLnet Labs Unbound 1.16.1及之前版本存在代码问题漏洞,该漏洞源于允许恶意用户继续触发恶意域名的可解析性。
CVSS Information
N/A
Vulnerability Type
N/A