CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
45.3%
Medium
Canonical Ubuntu
Xiang Li discovered that Unbound incorrectly handled delegation caching. A remote attacker could use this issue to keep rogue domain names resolvable long after they have been revoked. Update Instructions: Run sudo ua fix USN-5569-1
to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: libunbound2 – 1.6.7-1ubuntu2.5 unbound – 1.6.7-1ubuntu2.5 python3-unbound – 1.6.7-1ubuntu2.5 python-unbound – 1.6.7-1ubuntu2.5 unbound-anchor – 1.6.7-1ubuntu2.5 unbound-host – 1.6.7-1ubuntu2.5 libunbound-dev – 1.6.7-1ubuntu2.5 No subscription required
CVEs contained in this USN include: CVE-2022-30698, CVE-2022-30699.
Severity is medium unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
2022-09-29: Initial vulnerability report published.
Vendor | Product | Version | CPE |
---|---|---|---|
cloudfoundry | cflinuxfs3 | * | cpe:2.3:a:cloudfoundry:cflinuxfs3:*:*:*:*:*:*:*:* |
cloudfoundry | cf-deployment | * | cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* |