A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record.
This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1.
References
Link | Resource |
---|---|
https://kb.isc.org/docs/cve-2023-2829 | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20230703-0010/ | Third Party Advisory |
https://kb.isc.org/docs/cve-2023-2829 | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20230703-0010/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
21 Nov 2024, 07:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://kb.isc.org/docs/cve-2023-2829 - Vendor Advisory | |
References | () https://security.netapp.com/advisory/ntap-20230703-0010/ - Third Party Advisory |
03 Jul 2023, 19:11
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
First Time |
Netapp h410s
Netapp h700s Netapp h410s Firmware Netapp h500s Netapp h410c Netapp h410c Firmware Isc Netapp Netapp h500s Firmware Isc bind Netapp h700s Firmware Netapp h300s Firmware Netapp h300s Netapp active Iq Unified Manager |
|
CPE | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:a:isc:bind:*:*:*:*:supported_preview:*:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
|
References | (MISC) https://security.netapp.com/advisory/ntap-20230703-0010/ - Third Party Advisory | |
References | (MISC) https://kb.isc.org/docs/cve-2023-2829 - Vendor Advisory |
03 Jul 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Jun 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-21 17:15
Updated : 2024-11-21 07:59
NVD link : CVE-2023-2829
Mitre link : CVE-2023-2829
CVE.ORG link : CVE-2023-2829
JSON object : View
Products Affected
netapp
- active_iq_unified_manager
- h700s_firmware
- h300s
- h500s_firmware
- h410c
- h410s_firmware
- h410c_firmware
- h300s_firmware
- h500s
- h410s
- h700s
isc
- bind
CWE