Back

HIGH

unbound: command injection with data coming from a specially crafted IPSECKEY answer

Published Nov 19, 2019

Description

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

Affected products

Remediation

Red Hat statement

The versions of unbound as shipped in Red Hat Enterprise Linux 7 and 8 have `ipsecmod` disabled by default, even though it could be activated through the unbound-control command, it would only be executable by high-privilege users. Moreover, the `username` option is enabled, reducing the impact of a successful attack, and DNSSEC is used by default, preventing an attacker from modifying DNS packets on the wire. Finally, the default SELinux policies prevent unbound from running any shell command.

Red Hat mitigation

* Do not enable ipsecmod in the unbound.conf configuration file nor via unbound-control, if DNSSEC based Opportunistic IPsec is not used. * Use the `username` option in unbound.conf to make unbound drop privileges and reduce the impact of a successful attack. * Enable SELinux to prevent unbound from executing shell commands, apart from the expected one specified in the `ipsecmod-hook` option.

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Nov 19, 2019
Updated Aug 5, 2024
Reserved Nov 13, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Nov 26, 2019
Bugzilla 1776762

ENISA EUVD

Assigner mitre
Published Nov 19, 2019
Updated Aug 5, 2024

GitHub

No data