Infinite Loop Vulnerability in Unbound DNS Resolver by NLnet Labs
CVE-2020-12663

7.5HIGH

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
19 May 2020

What is CVE-2020-12663?

Unbound versions prior to 1.10.1 are susceptible to a vulnerability that causes an infinite loop when handling malformed DNS answers from upstream servers. This flaw arises from improper validation of DNS responses and can result in unresponsive behavior of the Unbound service, potentially leading to denial of service. It is essential for users to upgrade to the latest version of Unbound to mitigate this vulnerability and ensure optimal performance and reliability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.