Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16866

Опубликовано: 03 окт. 2019
Источник: redhat
CVSS3: 5.3

Описание

Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.

Отчет

This issue has been classified as having low security impact because:

  • per default, unbound is not configured to listen on a public interface
  • per default, the ACL is limited to localhost, so even if listening to a public interface, the crash cannot happen per default It mostly affects people running unbound as a "public" DNS resolver. Using such configurations, unbound has no valuable secrets that could be obtained by a successful attack, so at best the server crashes and restarts, resulting in an empty DNS cache. Sustained sending of packets would result in a DoS though.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundNot affected
Red Hat Enterprise Linux 7unboundNot affected
Red Hat Enterprise Linux 8unboundFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-822
https://bugzilla.redhat.com/show_bug.cgi?id=1767955unbound: uninitialized memory accesses leads to crash via a crafted NOTIFY query

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.

CVSS3: 7.5
nvd
больше 6 лет назад

Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.

CVSS3: 7.5
debian
больше 6 лет назад

Unbound before 1.9.4 accesses uninitialized memory, which allows remot ...

CVSS3: 7.5
github
больше 3 лет назад

Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость DNS-сервера Unbound, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3