USN-6998-1: Unbound vulnerabilities
It was discovered that Unbound incorrectly handled string comparisons, which could lead to a NULL pointer dereference. An attacker could potentially use this issue to cause a denial of service. (CVE-2024-43167) It was discovered that Unbound incorrectly handled memory in cfgmarkports, which could lead to a heap buffer overflow. A local attacker could potentially use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-43168)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6998-1?
The severity of USN-6998-1 is classified as a potential denial of service vulnerability.
How do I fix USN-6998-1?
To fix USN-6998-1, update your Unbound package to version 1.19.2-1ubuntu3.2 or higher on Ubuntu 24.04.
Which versions of Unbound are affected by USN-6998-1?
USN-6998-1 affects Unbound versions prior to 1.19.2-1ubuntu3.2 on Ubuntu 24.04 and older versions on earlier Ubuntu releases.
What is CVE-2024-43167 in relation to USN-6998-1?
CVE-2024-43167 is the identifier for the vulnerability addressed in USN-6998-1, which could lead to a NULL pointer dereference.
What are the symptoms of the vulnerability outlined in USN-6998-1?
The primary symptom of the USN-6998-1 vulnerability is a potential denial of service condition due to improper handling of string comparisons.