Lucene search

K
osvGoogleOSV:CVE-2023-2829
HistoryJun 21, 2023 - 5:15 p.m.

CVE-2023-2829

2023-06-2117:15:00
Google
osv.dev
10
cve-2023-2829
dns
remote termination

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

36.7%

A named instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (synth-from-dnssec) enabled can be remotely terminated using a zone with a malformed NSEC record.
This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1.

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

36.7%