ALAS2-2020-1463

Related Vulnerabilities: CVE-2020-10772  

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound. (CVE-2020-10772)

ALAS2-2020-1463


Amazon Linux 2 Security Advisory: ALAS-2020-1463
Advisory Release Date: 2020-07-14 02:51 Pacific
Advisory Updated Date: 2020-07-17 00:09 Pacific
Severity: Important
References: CVE-2020-10772 

Issue Overview:

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound. (CVE-2020-10772)


Affected Packages:

unbound


Issue Correction:
Run yum update unbound to update your system.

New Packages:
aarch64:
    unbound-1.6.6-5.amzn2.aarch64
    unbound-devel-1.6.6-5.amzn2.aarch64
    unbound-libs-1.6.6-5.amzn2.aarch64
    unbound-python-1.6.6-5.amzn2.aarch64
    unbound-debuginfo-1.6.6-5.amzn2.aarch64

i686:
    unbound-1.6.6-5.amzn2.i686
    unbound-devel-1.6.6-5.amzn2.i686
    unbound-libs-1.6.6-5.amzn2.i686
    unbound-python-1.6.6-5.amzn2.i686
    unbound-debuginfo-1.6.6-5.amzn2.i686

src:
    unbound-1.6.6-5.amzn2.src

x86_64:
    unbound-1.6.6-5.amzn2.x86_64
    unbound-devel-1.6.6-5.amzn2.x86_64
    unbound-libs-1.6.6-5.amzn2.x86_64
    unbound-python-1.6.6-5.amzn2.x86_64
    unbound-debuginfo-1.6.6-5.amzn2.x86_64