CVE-2020-12663: High severity unbound vulnerability
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12663?
The severity of CVE-2020-12663 is high, with a severity value of 7.5.
How does CVE-2020-12663 affect Unbound?
CVE-2020-12663 affects Unbound versions before 1.10.1 and can cause an infinite loop via malformed DNS answers received from upstream servers.
Which software versions are affected by CVE-2020-12663?
CVE-2020-12663 affects Unbound versions before 1.10.1 as well as specific versions of Debian, openSUSE Leap, Canonical Ubuntu Linux, and Fedora Linux.
How can I fix CVE-2020-12663?
To fix CVE-2020-12663, upgrade to Unbound version 1.10.1 or later. For Debian, Ubuntu, openSUSE Leap, and Fedora Linux, apply the specific remedies provided in the vulnerability details.
Where can I find more information about CVE-2020-12663?
You can find more information about CVE-2020-12663 in the provided references: http://www.openwall.com/lists/oss-security/2020/05/19/5, https://nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txt, and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1837609