• Simon Kelley's avatar
    DNSSEC fix for wildcard NSEC records. CVE-2017-15107 applies. · 4fe6744a
    Simon Kelley authored
    It's OK for NSEC records to be expanded from wildcards,
    but in that case, the proof of non-existence is only valid
    starting at the wildcard name, *.<domain> NOT the name expanded
    from the wildcard. Without this check it's possible for an
    attacker to craft an NSEC which wrongly proves non-existence
    in a domain which includes a wildcard for NSEC.
    4fe6744a
dnssec.c 56.7 KB