SB2019112048 - OS Command Injection in unbound (Alpine package)
Published: November 20, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS Command Injection (CVE-ID: CVE-2019-18934)
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the ipsec module. A remote attacker can pass specially crafted input to the application and execute arbitrary commands on the system.Successful exploitation of he vulnerability requires that unbound is compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=3286876175392eea49a76b591165c2e940681c66
- https://git.alpinelinux.org/aports/commit/?id=2986d9e83b920ffacf364d4ee6c2a5644a330152
- https://git.alpinelinux.org/aports/commit/?id=407d97afdcc1f3eabf878b21614f0cc72b0f336f
- https://git.alpinelinux.org/aports/commit/?id=85b36404206898cf9dc3221509b3e0ddac87c7ae
- https://git.alpinelinux.org/aports/commit/?id=ae112bcbe065a2f232ad8c641ab8da6b84f7e74c
- https://git.alpinelinux.org/aports/commit/?id=83d913bbc572f3811e9afbd81f9fb751a5e5be5b