Fixes a bug in NSEC3 validation handling code: Under specific circumstances checks of signatures over NSEC3 records are not done. As a result carefully crafted delegation responses (created through exploiting general DNS vulnerabilities such as DNS packet spoofing) can be used to downgrade an existing secure delegation to insecure.
Please log in to add feedback.
This update has been pushed to stable