forked from fkie-cad/nvd-json-data-feeds
-
Notifications
You must be signed in to change notification settings - Fork 0
/
CVE-2023-50868.json
104 lines (104 loc) · 4.3 KB
/
CVE-2023-50868.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
{
"id": "CVE-2023-50868",
"sourceIdentifier": "[email protected]",
"published": "2024-02-14T16:15:45.377",
"lastModified": "2024-02-29T03:15:06.817",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the \"NSEC3\" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations."
},
{
"lang": "es",
"value": "El aspecto Closest Encloser Proof del protocolo DNS (en RFC 5155 cuando se omite la gu\u00eda RFC 9276) permite a atacantes remotos provocar una denegaci\u00f3n de servicio (consumo de CPU para c\u00e1lculos SHA-1) a trav\u00e9s de respuestas DNSSEC en un ataque de subdominio aleatorio, tambi\u00e9n conocido como \" Problema NSEC3\". La especificaci\u00f3n RFC 5155 implica que un algoritmo debe realizar miles de iteraciones de una funci\u00f3n hash en determinadas situaciones."
}
],
"metrics": {},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2024/02/16/2",
"source": "[email protected]"
},
{
"url": "http://www.openwall.com/lists/oss-security/2024/02/16/3",
"source": "[email protected]"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2023-50868",
"source": "[email protected]"
},
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1219826",
"source": "[email protected]"
},
{
"url": "https://datatracker.ietf.org/doc/html/rfc5155",
"source": "[email protected]"
},
{
"url": "https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html",
"source": "[email protected]"
},
{
"url": "https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1",
"source": "[email protected]"
},
{
"url": "https://kb.isc.org/docs/cve-2023-50868",
"source": "[email protected]"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/",
"source": "[email protected]"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/",
"source": "[email protected]"
},
{
"url": "https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html",
"source": "[email protected]"
},
{
"url": "https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/",
"source": "[email protected]"
},
{
"url": "https://www.isc.org/blogs/2024-bind-security-release/",
"source": "[email protected]"
}
]
}