Unbound Security Restriction Bypass Vulnerability (CVE-2017-15105)
Unbound Security Restriction Bypass Vulnerability (CVE-2017-15105)
Release date:
Updated on:
Affected Systems:
Unbound <1.6.8
Description:
Bugtraq id: 102817
CVE (CAN) ID: CVE-2017-15105
Unbound is a recursive and cached DNS parser.
Unbound 1.6.8 and earlier versions have security vulnerabilities in the integrated wildcard NSEC record mode. After successful exploitation, attackers can bypass certain security restrictions and perform unauthorized operations.
<* Source: Ralph Dolmans
*>
Suggestion:
Vendor patch:
Unbound
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1507049
Https://access.redhat.com/security/cve/cve-2017-15105
Https://unbound.net/downloads/CVE-2017-15105.txt
Http://unbound.net/index.html