Shell Code Execution Vulnerability in Unbound IPSEC Module by NLnet Labs
CVE-2019-18934
7.3HIGH
What is CVE-2019-18934?
Unbound versions 1.6.4 through 1.9.4 have a security vulnerability in the IPSEC module that allows unauthenticated attackers to execute shell code. This vulnerability manifests when the Unbound DNS resolver is compiled with the --enable-ipsecmod flag and is configured to enable the IPSEC module. Successful exploitation requires the attacker to send a specially crafted response to the Unbound server, which can lead to severe consequences, including unauthorized access and control over the affected system.
