Lucene search

K
redhatRedHatRHSA-2022:0632
HistoryFeb 22, 2022 - 2:34 p.m.

(RHSA-2022:0632) Moderate: unbound security update

2022-02-2214:34:04
access.redhat.com
58
unbound
security update
cve-2019-25032
cve-2019-25034
dns resolver
denial of service
out-of-bounds write

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.007

Percentile

80.7%

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: integer overflow in the regional allocator via regional_alloc (CVE-2019-25032)

  • unbound: integer overflow in sldns_str2wire_dname_buf_origin can lead to an out-of-bounds write (CVE-2019-25034)

  • unbound: out-of-bounds write in sldns_bget_token_par (CVE-2019-25035)

  • unbound: assertion failure and denial of service in synth_cname (CVE-2019-25036)

  • unbound: assertion failure and denial of service in dname_pkt_copy via an invalid packet (CVE-2019-25037)

  • unbound: integer overflow in a size calculation in dnscrypt/dnscrypt.c (CVE-2019-25038)

  • unbound: integer overflow in a size calculation in respip/respip.c (CVE-2019-25039)

  • unbound: infinite loop via a compressed name in dname_pkt_copy (CVE-2019-25040)

  • unbound: assertion failure via a compressed name in dname_pkt_copy (CVE-2019-25041)

  • unbound: out-of-bounds write via a compressed name in rdata_copy (CVE-2019-25042)

  • unbound: symbolic link traversal when writing PID file (CVE-2020-28935)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.007

Percentile

80.7%