First published: Tue Nov 19 2019(Updated: )
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nlnetlabs Unbound | >=1.6.4<=1.9.4 | |
Fedoraproject Fedora | =31 | |
openSUSE | =15.1 | |
openSUSE | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18934 is a vulnerability in the ipsec module of Unbound 1.6.4 through 1.9.4 that can lead to shell code execution.
CVE-2019-18934 is considered to be a high severity vulnerability with a CVSS score of 7.3.
Unbound versions 1.6.4 through 1.9.4, Fedora 31, openSUSE Leap 15.1, and openSUSE Leap 15.2 are affected by CVE-2019-18934.
To exploit CVE-2019-18934, an attacker needs to send a specially crafted answer to the vulnerable Unbound server.
To mitigate CVE-2019-18934, it is recommended to update to a patched version of Unbound and disable the ipsec module if it is not needed.