Yasuhiro Morishita[verified]@OrangeMorishitaDisclosure
The snippet reports two new CVEs: one that allows zone data destruction via an APL record flaw, and another that bypasses client‑certificate authentication in XFR over TLS.
Upwind Security MDR[verified]@UpwindMDRDisclosure
A high‑impact stack‑based buffer overflow flaw in NSD 4.14.0 allows exploitation via crafted APL records leading to DoS or code execution, with no fix yet available.
日本レジストリサービス(JPRS)@JPRS_officialDisclosure
The notice reports the release of vulnerability information for NSD, listing four CVE identifiers, but does not provide technical details, PoC, or exploitation status.
Open Source Security mailing list@oss_securityDisclosure
NLnet Labs announces that four high‑severity CVEs in NSD have been patched in release 4.14.3, detailing heap overflow, DoS, stack write, and client certificate bypass issues.
日本レジストリサービス(JPRS)@JPRS_officialDisclosure
The JPRS newsletter announces that NSD has publicly disclosed vulnerability information for several CVEs, but provides no Proof‑of‑Concepts, exploitation details, patches, or other technical specifics.