First published: Tue May 19 2020(Updated: )
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. References: <a href="http://www.openwall.com/lists/oss-security/2020/05/19/5">http://www.openwall.com/lists/oss-security/2020/05/19/5</a> <a href="https://nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txt">https://nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txt</a>
Affected Software | Affected Version | How to fix |
---|---|---|
libunbound | <1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1837604 is considered critical due to the potential for an infinite loop from malformed DNS responses.
You can fix REDHAT-BUG-1837604 by upgrading to Unbound version 1.10.1 or later.
Not addressing REDHAT-BUG-1837604 may lead to a denial of service due to the endless loop caused by malicious DNS answers.
Unbound versions prior to 1.10.1 are affected by REDHAT-BUG-1837604.
You can determine your system's vulnerability to REDHAT-BUG-1837604 by checking the installed version of Unbound and comparing it to the known vulnerable versions.