CVE-2009-3602

Priority
Description
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records,
which allows remote attackers to cause secure delegations to be downgraded
via DNS spoofing or other DNS-related attacks in conjunction with crafted
delegation responses.
Notes
Package
Upstream:released (1.3.4-1)
Ubuntu 22.04 LTS (Jammy Jellyfish):not-affected
Patches:
More Information

Updated: 2022-02-10 23:38:55 UTC (commit acb3d89ab51f1d5e5543fa993969c0eb13c71f04)