user/nsd, user/unbound: multiple vulnerabilities
Bugzilla ID | 291 |
Alias(es) | CVE-2020-12662, CVE-2020-12663, CVE-2020-28935 |
Reporter | Max Rees (sroracle) |
Assignee | Alyx Wolcott |
Reported | 2020-05-19 17:00:04 -0500 |
Modified | 2020-12-09 17:23:35 -0600 |
Status | CONFIRMED |
Version | 1.0-RC1 |
Hardware | Adélie Linux / All |
Importance | --- / normal |
Package(s) | user/nsd, user/unbound |
URL | https://www.openwall.com/lists/oss-security/2020/05/19/5 |
Description
= CVE-2020-12662
Unbound can be tricked into amplifying an incoming query into a large
number of queries directed to a target.= CVE-2020-12663
Malformed answers from upstream name servers can be used to make
Unbound unresponsive.
Fixed in >= 1.10.1