First published: Tue May 19 2020(Updated: )
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nlnetlabs Unbound | <1.10.1 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
ubuntu/unbound | <1.6.7-1ubuntu2.3 | 1.6.7-1ubuntu2.3 |
ubuntu/unbound | <1.9.0-2ubuntu1.1 | 1.9.0-2ubuntu1.1 |
ubuntu/unbound | <1.9.4-2ubuntu1.1 | 1.9.4-2ubuntu1.1 |
ubuntu/unbound | <1.10.1-1 | 1.10.1-1 |
debian/unbound | 1.13.1-1+deb11u2 1.17.1-2+deb12u2 1.20.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-12663 is high, with a severity value of 7.5.
CVE-2020-12663 affects Unbound versions before 1.10.1 and can cause an infinite loop via malformed DNS answers received from upstream servers.
CVE-2020-12663 affects Unbound versions before 1.10.1 as well as specific versions of Debian, openSUSE Leap, Canonical Ubuntu Linux, and Fedora Linux.
To fix CVE-2020-12663, upgrade to Unbound version 1.10.1 or later. For Debian, Ubuntu, openSUSE Leap, and Fedora Linux, apply the specific remedies provided in the vulnerability details.
You can find more information about CVE-2020-12663 in the provided references: http://www.openwall.com/lists/oss-security/2020/05/19/5, https://nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txt, and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1837609