SUSE-SU-2022:0176-1
Dashboard / Vulnerabilities / SUSE-SU-2022:0176-1
SUSE-SU-2022:0176-1
Summary: Security update for unbound
Details: This update for unbound fixes the following issues: - CVE-2019-25031: Fixed configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack (bsc#1185382). - CVE-2019-25032: Fixed integer overflow in the regional allocator via regional_alloc (bsc#1185383). - CVE-2019-25033: Fixed integer overflow in the regional allocator via the ALIGN_UP macro (bsc#1185384). - CVE-2019-25034: Fixed integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write (bsc#1185385). - CVE-2019-25035: Fixed out-of-bounds write in sldns_bget_token_par (bsc#1185386). - CVE-2019-25036: Fixed assertion failure and denial of service in synth_cname (bsc#1185387). - CVE-2019-25037: Fixed assertion failure and denial of service in dname_pkt_copy via an invalid packet (bsc#1185388). - CVE-2019-25038: Fixed integer overflow in a size calculation in dnscrypt/dnscrypt.c (bsc#1185389). - CVE-2019-25039: Fixed integer overflow in a size calculation in respip/respip.c (bsc#1185390). - CVE-2019-25040: Fixed infinite loop via a compressed name in dname_pkt_copy (bsc#1185391). - CVE-2019-25041: Fixed assertion failure via a compressed name in dname_pkt_copy (bsc#1185392). - CVE-2019-25042: Fixed out-of-bounds write via a compressed name in rdata_copy (bsc#1185393). - CVE-2020-28935: Fixed symbolic link traversal when writing PID file (bsc#1179191).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20220176-1/, https://bugzilla.suse.com/1076963, https://bugzilla.suse.com/1112009, https://bugzilla.suse.com/1112033, https://bugzilla.suse.com/1179191, https://bugzilla.suse.com/1185382, https://bugzilla.suse.com/1185383, https://bugzilla.suse.com/1185384, https://bugzilla.suse.com/1185385, https://bugzilla.suse.com/1185386, https://bugzilla.suse.com/1185387, https://bugzilla.suse.com/1185388, https://bugzilla.suse.com/1185389, https://bugzilla.suse.com/1185390, https://bugzilla.suse.com/1185391, https://bugzilla.suse.com/1185392, https://bugzilla.suse.com/1185393, https://www.suse.com/security/cve/CVE-2019-25031, https://www.suse.com/security/cve/CVE-2019-25032, https://www.suse.com/security/cve/CVE-2019-25033, https://www.suse.com/security/cve/CVE-2019-25034, https://www.suse.com/security/cve/CVE-2019-25035, https://www.suse.com/security/cve/CVE-2019-25036, https://www.suse.com/security/cve/CVE-2019-25037, https://www.suse.com/security/cve/CVE-2019-25038, https://www.suse.com/security/cve/CVE-2019-25039, https://www.suse.com/security/cve/CVE-2019-25040, https://www.suse.com/security/cve/CVE-2019-25041, https://www.suse.com/security/cve/CVE-2019-25042, https://www.suse.com/security/cve/CVE-2020-28935
Affected packages
Package
Name: unbound
Purl: pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
