Back to search
CVE-2023-50868
Published: Feb 14, 2024
Modified: Nov 4, 2025
PUBLISHED
Description
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2024-2e26eccfcb
vendor-advisory
FEDORA-2024-e24211eff0
vendor-advisory
FEDORA-2024-21310568fa
vendor-advisory
FEDORA-2024-b0f9656a76
vendor-advisory
FEDORA-2024-4e36df9dfd
vendor-advisory
FEDORA-2024-499b9be35f
vendor-advisory
FEDORA-2024-c36c448396
vendor-advisory
FEDORA-2024-c967c7d287
vendor-advisory
FEDORA-2024-e00eceb11c
vendor-advisory
FEDORA-2024-fae88b73eb
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now