CVE-2024-33655: High severity Microsoft azl3 unbound 1.19.1-3 vulnerability
The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.
Other sources
The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases) aka the "DNSBomb" issue.
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33655?
CVE-2024-33655 is classified as a denial of service vulnerability that can lead to resource consumption.
How do I fix CVE-2024-33655?
To fix CVE-2024-33655, update the unbound package to version 1.9.4-2ubuntu1.6 or higher for Ubuntu, or the corresponding version for Debian.
Which versions of unbound are affected by CVE-2024-33655?
Affected versions of unbound include versions earlier than 1.9.4-2ubuntu1.6 for Ubuntu and lower than 1.20.0-1 for Debian.
Can CVE-2024-33655 be exploited remotely?
Yes, CVE-2024-33655 can be exploited by remote attackers through manipulated DNS queries.
What are the potential impacts of CVE-2024-33655?
The primary impact of CVE-2024-33655 is service disruption due to resource exhaustion caused by a burst of DNS responses.