USN-2484-1: Unbound vulnerability

Ubuntu Security Notice USN-2484-1

26th January, 2015

unbound vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 14.10
  • Ubuntu 14.04 LTS

Summary

Unbound could be made to consume resources if it received specially crafted
network traffic.

Software description

  • unbound
    – validating, recursive, caching DNS resolver

Details

Florian Maury discovered that Unbound incorrectly handled delegation. A
remote attacker could possibly use this issue to cause Unbound to consume
resources, resulting in a denial of service.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 14.10:
libunbound2

1.4.22-1ubuntu4.14.10.1
unbound

1.4.22-1ubuntu4.14.10.1
Ubuntu 14.04 LTS:
libunbound2

1.4.22-1ubuntu4.14.04.1
unbound

1.4.22-1ubuntu4.14.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2014-8602

Leave a Reply