Uncontrolled Recursion
Affecting unbound package, versions <1.9.0-2+deb10u2
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-12662
- CWE
- CWE-674
- Snyk ID
- SNYK-DEBIAN10-UNBOUND-569680
- Disclosed
- 19 May, 2020
- Published
- 19 May, 2020