First published: Wed May 27 2020(Updated: )
Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Unbound incorrectly handled certain queries. A remote attacker could use this issue to perform an amplification attack directed at a target. (CVE-2020-12662) It was discovered that Unbound incorrectly handled certain malformed answers. A remote attacker could possibly use this issue to cause Unbound to crash, resulting in a denial of service. (CVE-2020-12663)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libunbound8 | <1.9.4-2ubuntu1.1 | 1.9.4-2ubuntu1.1 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/unbound | <1.9.4-2ubuntu1.1 | 1.9.4-2ubuntu1.1 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/libunbound8 | <1.9.0-2ubuntu1.1 | 1.9.0-2ubuntu1.1 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/unbound | <1.9.0-2ubuntu1.1 | 1.9.0-2ubuntu1.1 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/libunbound2 | <1.6.7-1ubuntu2.3 | 1.6.7-1ubuntu2.3 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/unbound | <1.6.7-1ubuntu2.3 | 1.6.7-1ubuntu2.3 |
Ubuntu Linux | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12662
By performing an amplification attack directed at a target.
Ubuntu 20.04 with Unbound 1.9.4-2ubuntu1.1 and libunbound8 1.9.4-2ubuntu1.1.
Update to Unbound 1.9.4-2ubuntu1.1 and libunbound8 1.9.4-2ubuntu1.1.
You can find more information at the Ubuntu Security Advisory for CVE-2020-12662: https://ubuntu.com/security/CVE-2020-12662