| Name | CVE-2017-15105 |
| Description | A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-1264-1, DLA-1676-1 |
| Debian Bugs | 887733 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| unbound (PTS) | bullseye | 1.13.1-1+deb11u2 | fixed |
| bullseye (security) | 1.13.1-1+deb11u5 | fixed | |
| bookworm, bookworm (security) | 1.17.1-2+deb12u3 | fixed | |
| trixie | 1.22.0-2 | fixed | |
| forky, sid | 1.24.1-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| unbound | source | wheezy | 1.4.17-3+deb7u3 | DLA-1264-1 | ||
| unbound | source | jessie | 1.4.22-3+deb8u4 | DLA-1676-1 | ||
| unbound | source | stretch | 1.6.0-3+deb9u2 | |||
| unbound | source | (unstable) | 1.7.1-1 | 887733 |
https://unbound.net/downloads/CVE-2017-15105.txt
https://unbound.net/downloads/patch_cve_2017_15105.diff
https://medium.com/nlnetlabs/the-peculiar-case-of-nsec-processing-using-expanded-wildcard-records-ae8285f236be