漏洞信息详情
Unbound 注入漏洞
漏洞简介
Unbound是荷兰NLnet Labs(Nlnet Labs)基金会的一款支持验证递归和缓存的DNS解析器。
Unbound 1.9.5之前版本存在安全漏洞,该漏洞允许在成功的man-in-the-middle攻击明文HTTP会话时,在create unbinding ad servers.sh中进行配置注入。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://lists.nlnetlabs.nl/pipermail/unbound-users/2019-December/
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/05/msg00007.html
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210507-0007/
来源:MISC
链接:https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162492/Ubuntu-Security-Notice-USN-4938-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1570
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-25031
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021051030
受影响实体
暂无
补丁
- Unbound 注入漏洞的修复措施<!--2021-4-27-->
还没有评论,来说两句吧...