[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2023-50868Date: (C)2024-02-15   (M)2024-05-16


The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score :
Exploit Score: Exploit Score:
Impact Score: Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector:
Attack Complexity: Access Complexity:
Privileges Required: Authentication:
User Interaction: Confidentiality:
Scope: Integrity:
Confidentiality: Availability:
Integrity:  
Availability:  
  
Reference:
FEDORA-2024-21310568fa
FEDORA-2024-2e26eccfcb
FEDORA-2024-499b9be35f
FEDORA-2024-4e36df9dfd
FEDORA-2024-b0f9656a76
FEDORA-2024-c36c448396
FEDORA-2024-c967c7d287
FEDORA-2024-e00eceb11c
FEDORA-2024-e24211eff0
FEDORA-2024-fae88b73eb
https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
http://www.openwall.com/lists/oss-security/2024/02/16/3
https://access.redhat.com/security/cve/CVE-2023-50868
https://bugzilla.suse.com/show_bug.cgi?id=1219826
https://datatracker.ietf.org/doc/html/rfc5155
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html
https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1
https://kb.isc.org/docs/cve-2023-50868
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html
https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/
https://security.netapp.com/advisory/ntap-20240307-0008/
https://www.isc.org/blogs/2024-bind-security-release/

OVAL    62
oval:org.secpod.oval:def:127283
oval:org.secpod.oval:def:708768
oval:org.secpod.oval:def:98708
oval:org.secpod.oval:def:127282
...
XCCDF    1

© SecPod Technologies