5

CVE-2008-1184

The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dnssec-toolsDnssec-tools Version <= 1.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.27% 0.66
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/29095
Vendor Advisory
http://secunia.com/advisories/29127
Patch
Vendor Advisory
http://sourceforge.net/mailarchive/forum.php?thread_name=sdlk5lolzj.fsf%40wes.hardakers.net&forum_name=dnssec-tools-users
http://www.securityfocus.com/bid/27998
http://www.vupen.com/english/advisories/2008/0673/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/40836
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00820.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00845.html