USN-4374-1: Unbound vulnerabilities
Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Unbound incorrectly handled certain queries. A remote attacker could use this issue to perform an amplification attack directed at a target. (CVE-2020-12662) It was discovered that Unbound incorrectly handled certain malformed answers. A remote attacker could possibly use this issue to cause Unbound to crash, resulting in a denial of service. (CVE-2020-12663)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this advisory?
CVE-2020-12662
How can a remote attacker exploit this vulnerability?
By performing an amplification attack directed at a target.
What is the affected software?
Ubuntu 20.04 with Unbound 1.9.4-2ubuntu1.1 and libunbound8 1.9.4-2ubuntu1.1.
How can I fix this vulnerability?
Update to Unbound 1.9.4-2ubuntu1.1 and libunbound8 1.9.4-2ubuntu1.1.
Where can I find more information about this vulnerability?
You can find more information at the Ubuntu Security Advisory for CVE-2020-12662: https://ubuntu.com/security/CVE-2020-12662