TROYANOSYVIRUS
Retour aux CVEs

CVE-2023-50387

HIGH
7.5

Description

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

Details CVE

Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie2/14/2024
Derniere modification11/4/2025
Sourcenvd
Observations honeypot0

Produits affectes

fedoraproject:fedoraisc:bindmicrosoft:windows_server_2008microsoft:windows_server_2012microsoft:windows_server_2016microsoft:windows_server_2019microsoft:windows_server_2022microsoft:windows_server_2022_23h2nic:knot_resolvernlnetlabs:unboundpowerdns:recursorredhat:enterprise_linuxthekelleys:dnsmasq

Faiblesses (CWE)

CWE-770CWE-770

References

http://www.openwall.com/lists/oss-security/2024/02/16/2(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2024/02/16/3(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/security/cve/CVE-2023-50387(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.suse.com/show_bug.cgi?id=1219823(af854a3a-2127-422b-91ae-364da2661108)
https://kb.isc.org/docs/cve-2023-50387(af854a3a-2127-422b-91ae-364da2661108)
https://news.ycombinator.com/item?id=39367411(af854a3a-2127-422b-91ae-364da2661108)
https://news.ycombinator.com/item?id=39372384(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20240307-0007/(af854a3a-2127-422b-91ae-364da2661108)
https://www.athene-center.de/aktuelles/key-trap(af854a3a-2127-422b-91ae-364da2661108)
https://www.isc.org/blogs/2024-bind-security-release/(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.