CVE-2023-50387 |
BDSA-2024-0337 |
High |
Feb 14, 2024 |
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU c
more...
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
less...
|
2.88, 2.87, v2.84, 2.83, 2.82, 2.80, 2.79, 2.78, 2.77, 2.76
|
CVE-2023-28450 |
BDSA-2023-0574 |
High |
Mar 15, 2023 |
An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2
more...
An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.
less...
|
2.88, 2.87, v2.84, 2.83, 2.82, 2.80, 2.79, 2.78, 2.77, 2.76
|
BDSA-2024-0359 |
|
Medium |
Feb 16, 2024 |
Implementations of DNSSEC, the Security Extensions of DNS, can be impacted by design features of the specification that could allow for the excessive c
more...
Implementations of DNSSEC, the Security Extensions of DNS, can be impacted by design features of the specification that could allow for the excessive consumption of CPU resources on a DNSSEC-validating resolver when using NSEC3.
Affected implementations can spend valuable CPU cycles on SHA1 hashing where an attacker is able to select or create a DNSSEC-signed zone with NSEC3 parameters that are configured in a way to be in excess of recommended best practices using extra iterations, and then launch a random subdomain attack against the zone.
Where an attacker is able to force a target to carry out this work, performance can be heavily impacted and result in availability issues for other clients.
less...
|
|