Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18934

Опубликовано: 19 нояб. 2019
Источник: debian
EPSS Низкий

Описание

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
unboundfixed1.9.6-1package
unboundnot-affectedstretchpackage
unboundnot-affectedjessiepackage

Примечания

  • Debian binary packages not built with --enable-ipsecmod

  • https://nlnetlabs.nl/downloads/unbound/CVE-2019-18934.txt

  • https://github.com/NLnetLabs/unbound/commit/09845779d5f2c96e3064ff398cad65c08357cfbf

  • https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/

EPSS

Процентиль: 76%
0.00961
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 6 лет назад

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

CVSS3: 5.6
redhat
около 6 лет назад

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

CVSS3: 7.3
nvd
около 6 лет назад

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

CVSS3: 7.3
github
больше 3 лет назад

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

oracle-oval
почти 6 лет назад

ELSA-2020-1716: unbound security update (MODERATE)

EPSS

Процентиль: 76%
0.00961
Низкий