Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
2019-10-03T19:15:09.550
2024-11-21T04:31:14.060
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nlnetlabs | unbound | < 1.9.4 | Yes |
Operating System | canonical | ubuntu_linux | 19.04 | Yes |