GHSA-fw3j-5rrr-7j3rMediumCVSS 4.9

Unless a nameserver is providing authoritative service for one or more zones and at least one...

Published
May 24, 2022
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

🔗 References (12)