← العودة للجدول
bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards
📅 2026-08-17 07:00:15
🟢 Low 🔥 No Vulners Vulnerability Threat Intel

📋 الوصف الكامل

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set synth-from-dnssec yes; which is

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

📡 المصدر

Vulners

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ←