Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25031

Опубликовано: 11 дек. 2019
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation

A flaw was found in unbound. The create_unbound_ad_servers.sh bash script does not properly sanitize input data, which is retrieved using an unencrypted, unauthenticated HTTP request, before writing the configuration file allowing a man-in-the-middle attack. The highest threat from this vulnerability is to data integrity and system availability.

Отчет

This issue did not affect the versions of unbound as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include the vulnerable script create_unbound_ad_servers.sh.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundOut of support scope
Red Hat Enterprise Linux 7unboundNot affected
Red Hat Enterprise Linux 8unboundNot affected
Red Hat Enterprise Linux 9unboundNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1954809unbound: configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session

EPSS

Процентиль: 74%
0.00811
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 5 лет назад

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation

CVSS3: 5.9
nvd
почти 5 лет назад

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation

CVSS3: 5.9
debian
почти 5 лет назад

Unbound before 1.9.5 allows configuration injection in create_unbound_ ...

CVSS3: 5.9
github
больше 3 лет назад

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session.

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость компонента create_unbound_ad_servers.sh DNS-сервера Unbound, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 74%
0.00811
Низкий

5.9 Medium

CVSS3