Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10772

Опубликовано: 10 июн. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundNot affected
Red Hat Enterprise Linux 8unboundNot affected
Red Hat Enterprise Linux 7unboundFixedRHSA-2020:264222.06.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-406->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1846026unbound: incomplete fix for CVE-2020-12662 in RHEL7

EPSS

Процентиль: 53%
0.00303
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.

CVSS3: 7.5
nvd
около 5 лет назад

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.

CVSS3: 7.5
debian
около 5 лет назад

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Ha ...

github
больше 3 лет назад

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.

oracle-oval
больше 5 лет назад

ELSA-2020-2642: unbound security update (IMPORTANT)

EPSS

Процентиль: 53%
0.00303
Низкий

7.5 High

CVSS3