SB2020051946 - Infinite loop in unbound (Alpine package)
Published: May 19, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2020-12663)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when parsing DNS responses. A remote attacker can send a specially crafted DNS response to the server, consume all available system resources and cause denial of service conditions.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=3286876175392eea49a76b591165c2e940681c66
- https://git.alpinelinux.org/aports/commit/?id=75675628d024650eb8edf60c6d81f67d3e563668
- https://git.alpinelinux.org/aports/commit/?id=e09fa9fd69e509b0de3041baab65aac63b246b0d
- https://git.alpinelinux.org/aports/commit/?id=2986d9e83b920ffacf364d4ee6c2a5644a330152