All errata/p8/ALT-PU-2020-2027-1
ALT-PU-2020-2027-1

Package update unbound in branch p8

Version1.10.2-alt0.M80P.1
Published2020-05-27
Max severityHIGH
Severity:

Closed issues (2)

CVE-2020-12662
HIGH7.5

Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

Published: 2020-05-19Modified: 2024-11-21
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
CVE-2020-12663
HIGH7.5

Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

Published: 2020-05-19Modified: 2024-11-21
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H