Debian Security Advisory

DSA-4694-1 unbound -- security update

Date Reported:
26 May 2020
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2020-12662, CVE-2020-12663.
More information:

Two vulnerabiliites have been discovered in Unbound, a recursive-only caching DNS server; a traffic amplification attack against third party authoritative name servers (NXNSAttack) and insufficient sanitisation of replies from upstream servers could result in denial of service via an infinite loop.

The version of Unbound in the oldstable distribution (stretch) is no longer supported. If these security issues affect your setup, you should upgrade to the stable distribution (buster).

For the stable distribution (buster), these problems have been fixed in version 1.9.0-2+deb10u2.

We recommend that you upgrade your unbound packages.

For the detailed security status of unbound please refer to its security tracker page at: