Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Packet of death with DNSCrypt
Vulnerability Description
NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.
CVSS Information
N/A
Vulnerability Type
缺失特殊元素净化处理不恰当
Vulnerability Title
NLnet Labs Unbound 缓冲区错误漏洞
Vulnerability Description
NLnet Labs Unbound是NLnet Labs开源的一个高性能DNS解析器。 NLnet Labs Unbound 1.6.2版本至1.25.0版本存在缓冲区错误漏洞,该漏洞源于DNSCrypt数据包读取过程下溢可能导致堆溢出。恶意攻击者可利用单个恶意DNSCrypt查询触发漏洞,其解密明文完全由0x00字节组成且不包含预期的0x80标记,导致Unbound读取超出必要字节。基于底层内存分配器和内存布局,可能导致堆溢出并引发崩溃。
CVSS Information
N/A
Vulnerability Type
N/A