Alerts This Week
Warning Icon 1 975
Alerts This Week
Warning Icon 1 975

Ubuntu 20.04 LTS: USN-4374-1 Critical Unbound Denial of Service Fix

ubuntu
Calendar Grey May 27, 2020
Dist Ubuntu Esm H88
Multiple vulnerabilities in Unbound resolved in Ubuntu 20.04, 19.10, and 18.04 LTS. Ensure you update your systems quickly for better security.
Several security issues were fixed in Unbound.

Summary

Several security issues were fixed in Unbound.

Software Description:

- unbound: validating, recursive, caching DNS resolver

Details:

Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Unbound

incorrectly handled certain queries. A remote attacker could use this issue

to perform an amplification attack directed at a target. (CVE-2020-12662)

It was discovered that Unbound incorrectly handled certain malformed

answers. A remote attacker could possibly use this issue to cause Unbound

to crash, resulting in a denial of service. (CVE-2020-12663)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libunbound8                     1.9.4-2ubuntu1.1
  unbound                         1.9.4-2ubuntu1.1

Ubuntu 19.10:
  libunbound8                     1.9.0-2ubuntu1.1
  unbound                         1.9.0-2ubuntu1.1

Ubuntu 18.04 LTS:
  libunbound2                     1.6.7-1ubuntu2.3
  unbound                         1.6.7-1ubuntu2.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4374-1

CVE-2020-12662, CVE-2020-12663

Severity
critical
Lowest
Low
Medium
High
Critical

May 27, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here