Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 16 Feb 2024 20:27:51 +0100
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Unbound: disclosure of CVE-2023-50387 and CVE-2023-50868 DNSSEC validation vulnerabilities

On Fri, Feb 16, 2024 at 11:10:08AM -0800, Alan Coopersmith wrote:
> For those who want more details on the CVE-2023-50387 flaw itself,
> the researchers have now published their paper at
> https://www.athene-center.de/en/keytrap (see the PDF link in the
> "Technical Report" section).

Also, ISC published a blog post on both DNSSEC issues:

https://www.isc.org/blogs/2024-bind-security-release/

And there's a collection of many other related links here:

https://infosec.exchange/@tychotithonus/111924626712765292

It's possibly still being updated.  May need to click "SHOW MORE" to see
them all.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.