imPC@ndo EN

Tracker / CVE-2023-50387

CVE-2023-50387

Alta 7.5

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

Prodotti e versioni affette

fedoraproject fedora
isc bind · 9.0.0 → 9.16.46
isc bind · 9.18.0 → 9.18.22
isc bind · 9.19.0 → 9.19.20
microsoft windows_server_2008
microsoft windows_server_2012
microsoft windows_server_2016
microsoft windows_server_2019
microsoft windows_server_2022
microsoft windows_server_2022_23h2
nic knot_resolver · … → 5.71
nlnetlabs unbound · … → 1.19.1
powerdns recursor · 4.8.0 → 4.8.6
powerdns recursor · 4.9.0 → 4.9.3
powerdns recursor · 5.0.0 → 5.0.2
redhat enterprise_linux
thekelleys dnsmasq · … → 2.90

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti