Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

SUSE: 2020:1819-1 Important: Unbound Security Issues Resolved

suse
Calendar Grey July 1, 2020
Scroller Suse
SUSE Security Update: Security update for unbound __________________________________________________
An update that fixes three vulnerabilities is now available

Summary

This update for unbound fixes the following issues: - CVE-2020-12662: Fixed an issue where unbound could have been tricked into amplifying an incoming query into a large number of queries directed to a target (bsc#1171889). - CVE-2020-12663: Fixed an issue where malformed answers from upstream name servers could have been used to make unbound unresponsive (bsc#1171889). - CVE-2019-18934: Fixed a vulnerability in the IPSec module which could have allowed code execution after receiving a special crafted answer (bsc#1157268). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15:

References

#1157268 #1171889

Cross- CVE-2019-18934 CVE-2020-12662 CVE-2020-12663

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-ESPOS

https://www.suse.com/security/cve/CVE-2019-18934.html

https://www.suse.com/security/cve/CVE-2020-12662.html

https://www.suse.com/security/cve/CVE-2020-12663.html

https://bugzilla.suse.com/1157268

https://bugzilla.suse.com/1171889

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1819-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.