UBUNTU-CVE-2023-50387
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-50387
UBUNTU-CVE-2023-50387
Summary:
Details: Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
References: https://ubuntu.com/security/CVE-2023-50387, https://kb.isc.org/docs/cve-2023-50387, https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html, https://www.knot-resolver.cz/2024-02-13-knot-resolver-5.7.1.html, https://blog.powerdns.com/2024/02/13/powerdns-recursor-4-8-6-4-9-3-5-0-2-released, https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/, https://nlnetlabs.nl/downloads/unbound/CVE-2023-50387_CVE-2023-50868.txt, https://ubuntu.com/security/notices/USN-6633-1, https://ubuntu.com/security/notices/USN-6642-1, https://ubuntu.com/security/notices/USN-6657-1, https://ubuntu.com/security/notices/USN-6665-1, https://ubuntu.com/security/notices/USN-6723-1, https://www.cve.org/CVERecord?id=CVE-2023-50387, https://ubuntu.com/security/notices/USN-6657-2
Affected packages
Package
Name: bind9
Purl: pkg:deb/ubuntu/bind9?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
