unbound vulnerability

Related Vulnerabilities: CVE-2017-15105  

A security issue was fixed in Unbound.

Ralph Dolmans and Karst Koymans discovered that Unbound did not properly handle certain NSEC records. An attacker could use this to to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick Unbound into accepting a NODATA proof.

7 June 2018

unbound vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 18.04 LTS
  • Ubuntu 17.10
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

A security issue was fixed in Unbound.

Software Description

  • unbound - validating, recursive, caching DNS resolver

Details

Ralph Dolmans and Karst Koymans discovered that Unbound did not properly handle certain NSEC records. An attacker could use this to to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick Unbound into accepting a NODATA proof.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 18.04 LTS
libunbound2 - 1.6.7-1ubuntu2.1
unbound - 1.6.7-1ubuntu2.1
Ubuntu 17.10
libunbound2 - 1.6.5-1ubuntu0.2
unbound - 1.6.5-1ubuntu0.2
Ubuntu 16.04 LTS
libunbound2 - 1.5.8-1ubuntu1.1
unbound - 1.5.8-1ubuntu1.1
Ubuntu 14.04 LTS
libunbound2 - 1.4.22-1ubuntu4.14.04.3
unbound - 1.4.22-1ubuntu4.14.04.3

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References