A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Unbound1.13 Extra | unbound | 2024-06-19 20:39 | ALAS2UNBOUND-2024-002 |
Amazon Linux 2 - Unbound1.17 Extra | unbound | 2024-06-19 20:39 | ALAS2UNBOUND-1.17-2024-002 |
Amazon Linux 2023 | unbound | 2024-04-25 16:40 | ALAS2023-2024-604 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
NVD | CVSSv3 | 8.0 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |