目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%

CVE-2024-8508— NLnet Unbound 安全漏洞

CVSS 5.3 · Medium EPSS 0.23% · P45
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-8508 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Unbounded name compression could lead to Denial of Service
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. The vulnerability can be exploited by a malicious actor querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations it is willing to do per packet. Packets that need more compression will result in semi-compressed packets or truncated packets, even on TCP for huge messages, to avoid locking the CPU for long. This change should not affect normal DNS traffic.
来源: 美国国家漏洞数据库 NVD
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
循环条件输入未经检查
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
NLnet Unbound 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
NLnet Unbound是荷兰NLnet团队的一款开源DNS服务器。 NLnet Unbound 1.21.0及之前版本存在安全漏洞,该漏洞源于处理包含非常大的RRsets的回复时所需执行的名称压缩操作,可能导致性能下降或服务拒绝。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
NLnet LabsUnbound 0 ~ 1.21.0 -

二、漏洞 CVE-2024-8508 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-8508 的情报信息

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-8508

暂无评论


发表评论