VDB
CVE-2011-4528
CVE-2011-4528
PUBLISHED
CVSS 5 MEDIUM
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
EPSS 2.91% · 86.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.91%
86.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| unbound | unbound | 1.4.6, 0, 0.0 |
| n/a | n/a | n/a |
Timeline
- Dec 20, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- http://unbound.nlnetlabs.nl/downloads/CVE-2011-4528.txt url
- 47326 third-party-advisory
- VU#209659 third-party-advisory
- DSA-2370 vendor-advisory
- FEDORA-2011-17337 vendor-advisory
- 77909 vdb
- FEDORA-2011-17282 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4528 advisory