Information Disclosure and Denial of Service in Unbound by Red Hat
CVE-2020-10772

7.5HIGH

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
27 November 2020

What is CVE-2020-10772?

An incomplete fix related to a previous vulnerability in Unbound has been identified, which could potentially allow attackers to amplify incoming queries into a larger number of requests aimed at a specified target. This flaw is part of a broader security concern associated with Red Hat Enterprise Linux 7, following erratum RHSA-2020:2414, and highlights ongoing risks to systems still utilizing vulnerable versions of Unbound.

Affected Version(s)

unbound unbound-1.6.6-5.el7_8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.