漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Novel "ghost domain names" attack by updating almost expired delegation information
Vulnerability Description
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NLnet Labs Unbound 代码问题漏洞
Vulnerability Description
NLnet Labs Unbound是NLnet Labs公司的一款开源DNS服务器。 NLnet Labs Unbound 1.16.1及之前版本存在代码问题漏洞,该漏洞源于允许恶意用户继续触发恶意域名的可解析性。
CVSS Information
N/A
Vulnerability Type
N/A