CVE-2011-1922: Medium severity unbound vulnerability
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1922?
CVE-2011-1922 is classified as a denial of service vulnerability, which can cause the Unbound DNS resolver to crash.
How do I fix CVE-2011-1922?
To mitigate CVE-2011-1922, upgrade to Unbound version 1.4.10 or later where the vulnerability is resolved.
What software versions are affected by CVE-2011-1922?
CVE-2011-1922 affects Unbound versions from 1.0.0 up to 1.4.9.
What type of attack does CVE-2011-1922 enable?
CVE-2011-1922 enables remote attackers to conduct denial of service attacks via crafted DNS requests.
Is CVE-2011-1922 exploitable over the internet?
Yes, CVE-2011-1922 can be exploited by remote attackers targeting vulnerable instances of the Unbound DNS resolver.