Name | CVE-2017-15105 |
Description | A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1264-1, DLA-1676-1 |
Debian Bugs | 887733 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
unbound (PTS) | bullseye | 1.13.1-1+deb11u2 | fixed |
bullseye (security) | 1.13.1-1+deb11u4 | fixed | |
bookworm, bookworm (security) | 1.17.1-2+deb12u2 | fixed | |
sid, trixie | 1.22.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
unbound | source | wheezy | 1.4.17-3+deb7u3 | DLA-1264-1 | ||
unbound | source | jessie | 1.4.22-3+deb8u4 | DLA-1676-1 | ||
unbound | source | stretch | 1.6.0-3+deb9u2 | |||
unbound | source | (unstable) | 1.7.1-1 | 887733 |
https://unbound.net/downloads/CVE-2017-15105.txt
https://unbound.net/downloads/patch_cve_2017_15105.diff
https://medium.com/nlnetlabs/the-peculiar-case-of-nsec-processing-using-expanded-wildcard-records-ae8285f236be