First published: Tue May 19 2020(Updated: )
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nlnetlabs Unbound | <1.10.1 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
redhat/unbound | <1.10.1 | 1.10.1 |
ubuntu/unbound | <1.6.7-1ubuntu2.3 | 1.6.7-1ubuntu2.3 |
ubuntu/unbound | <1.9.0-2ubuntu1.1 | 1.9.0-2ubuntu1.1 |
ubuntu/unbound | <1.9.4-2ubuntu1.1 | 1.9.4-2ubuntu1.1 |
ubuntu/unbound | <1.10.1-1 | 1.10.1-1 |
debian/unbound | 1.13.1-1+deb11u2 1.17.1-2+deb12u2 1.20.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2020-12662.
The severity level of CVE-2020-12662 is high.
The affected software for CVE-2020-12662 includes Unbound versions 1.6.7-1ubuntu2.3, 1.9.0-2ubuntu1.1, 1.10.1-1, 1.9.4-2ubuntu1.1, and 1.10.1.
The remedy for CVE-2020-12662 is to update Unbound to version 1.10.1 or apply the specific versions mentioned for each affected software.
More information about CVE-2020-12662 can be found at the following references: [link1](http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00067.html), [link2](http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00069.html), and [link3](http://www.nxnsattack.com).