Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-30699
HistoryAug 01, 2022 - 12:00 a.m.

CVE-2022-30699

2022-08-0100:00:00
ubuntu.com
ubuntu.com
29
nlnet labs unbound
ghost domain names" attack
delayed response
cached delegation information
vulnerability
fixed version 1.16.2

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

45.3%

NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a
novel type of the “ghost domain names” attack. The vulnerability works by
targeting an Unbound instance. Unbound is queried for a rogue domain name
when the cached delegation information is about to expire. The rogue
nameserver delays the response so that the cached delegation information is
expired. Upon receiving the delayed answer containing the delegation
information, Unbound overwrites the now expired entries. This action can be
repeated when the delegation information is about to expire making the
rogue delegation information ever-updating. From version 1.16.2 on, Unbound
stores the start time for a query and uses that to decide if the cached
delegation information can be overwritten.

Bugs

Notes

Author Note
mdeslaur same commit as CVE-2022-30698

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

45.3%