Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

SUSE: Security Advisory (SUSE-SU-2022:0176-1)

Information

Severity

Severity

High

Family

Family

SuSE Local Security Checks

CVSSv2 Base

CVSSv2 Base

7.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

The remote host is missing an update for the 'unbound' package(s) announced via the SUSE-SU-2022:0176-1 advisory.

Insight

Insight

This update for unbound fixes the following issues: CVE-2019-25031: Fixed configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack (bsc#1185382). CVE-2019-25032: Fixed integer overflow in the regional allocator via regional_alloc (bsc#1185383). CVE-2019-25033: Fixed integer overflow in the regional allocator via the ALIGN_UP macro (bsc#1185384). CVE-2019-25034: Fixed integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write (bsc#1185385). CVE-2019-25035: Fixed out-of-bounds write in sldns_bget_token_par (bsc#1185386). CVE-2019-25036: Fixed assertion failure and denial of service in synth_cname (bsc#1185387). CVE-2019-25037: Fixed assertion failure and denial of service in dname_pkt_copy via an invalid packet (bsc#1185388). CVE-2019-25038: Fixed integer overflow in a size calculation in dnscrypt/dnscrypt.c (bsc#1185389). CVE-2019-25039: Fixed integer overflow in a size calculation in respip/respip.c (bsc#1185390). CVE-2019-25040: Fixed infinite loop via a compressed name in dname_pkt_copy (bsc#1185391). CVE-2019-25041: Fixed assertion failure via a compressed name in dname_pkt_copy (bsc#1185392). CVE-2019-25042: Fixed out-of-bounds write via a compressed name in rdata_copy (bsc#1185393). CVE-2020-28935: Fixed symbolic link traversal when writing PID file (bsc#1179191).

Affected Software

Affected Software

'unbound' package(s) on SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, SUSE Enterprise Storage 7, SUSE Linux Enterprise High Performance Computing 15-SP1, SUSE Linux Enterprise High Performance Computing 15-SP2, SUSE Linux Enterprise Module for Basesystem 15-SP3, SUSE Linux Enterprise Module for Basesystem 15-SP4, SUSE Linux Enterprise Server 15-SP1, SUSE Linux Enterprise Server 15-SP2, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Linux Enterprise Server for SAP 15-SP2, SUSE Manager Proxy 4.1, SUSE Manager Retail Branch Server 4.1, SUSE Manager Server 4.1.

Detection Method

Detection Method

Checks if a vulnerable package version is present on the target host.

Solution

Solution

Please install the updated package(s).