Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a… | HappeningNow.news

Cybersecurity · 1 views

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

Source Summary Published 2h 33m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 1 Community interest
Brief read Under 1 min brief 46 words

Summary

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

Read original at The Hackernews

Coverage Context

Part of DNS coverage 20 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page