CVE-2012-1192: Unbound

Medium severity, CVSS 6.4. EPSS: 1.3% chance of exploitation in the next 30 days.

The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

Affected products

  • Unbound Unbound: up to and including 1.4.10; version 0.0 only; version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; …

Published 2012-02-17. Last modified 2026-06-16.