SB2020051945 - Input validation error in unbound (Alpine package)
Published: May 19, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-12662)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing DNS responses. A remote attacker who controls a malicious DNS server can send a specially crafted response and perform a denial of service (DoS) attack against third-party DNS servers.
The attack is triggered by random subdomains in the NSDNAME in NS records.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=3286876175392eea49a76b591165c2e940681c66
- https://git.alpinelinux.org/aports/commit/?id=75675628d024650eb8edf60c6d81f67d3e563668
- https://git.alpinelinux.org/aports/commit/?id=e09fa9fd69e509b0de3041baab65aac63b246b0d
- https://git.alpinelinux.org/aports/commit/?id=2986d9e83b920ffacf364d4ee6c2a5644a330152