Input validation error in Unbound - CVE-2020-10772
Published: July 15, 2020 / Updated: July 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due incomplete fix for vulnerability SB2020052127 #1 (CVE-2020-12662). A remote attacker who controls a malicious DNS server can send a specially crafted response and perform a denial of service (DoS) attack against third-party DNS servers.
Affected software
unbound (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
How to mitigate CVE-2020-10772
unbound (Red Hat package) - update to 1.6.6-5.el7_8