Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NRDelegation Attack
Vulnerability Description
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the attack and the replies, different limits could be reached. From version 1.16.3 on, Unbound introduces fixes for better performance when under load, by cutting opportunistic queries for nameserver discovery and DNSKEY prefetching and limiting the number of times a delegation point can issue a cache lookup for missing records.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NLnet Labs Unbound 资源管理错误漏洞
Vulnerability Description
NLnet Labs Unbound是NLnet Labs公司的一款开源DNS服务器。 NLnet Labs Unbound 1.16.3 之前版本存在安全漏洞,该漏洞源于Unbound不会受到高CPU使用率的影响,但仍需要资源来解决恶意委托,会不断尝试解析记录,直到达到硬限制。根据攻击和回复的性质,可能会达到不同的限制。
CVSS Information
N/A
Vulnerability Type
N/A