unbound: command injection with data coming from a specially crafted IPSECKEY answer
Published Nov 19, 2019
7.3
HIGHCVSS 3.1
EPSS 3.20%
Description
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
unbound-0:1.7.3-10.el8
Fixed · RHSA-2020:1716
Red Hat Enterprise Linux 6
unbound
Not affected
Red Hat Enterprise Linux 7
unbound
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | unbound-0:1.7.3-10.el8 | Fixed | RHSA-2020:1716 |
| Red Hat Enterprise Linux 6 | unbound | Not affected | n/a |
| Red Hat Enterprise Linux 7 | unbound | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The versions of unbound as shipped in Red Hat Enterprise Linux 7 and 8 have `ipsecmod` disabled by default, even though it could be activated through the unbound-control command, it would only be executable by high-privilege users. Moreover, the `username` option is enabled, reducing the impact of a successful attack, and DNSSEC is used by default, preventing an attacker from modifying DNS packets on the wire. Finally, the default SELinux policies prevent unbound from running any shell command.
Red Hat mitigation
* Do not enable ipsecmod in the unbound.conf configuration file nor via unbound-control, if DNSSEC based Opportunistic IPsec is not used. * Use the `username` option in unbound.conf to make unbound drop privileges and reduce the impact of a successful attack. * Enable SELinux to prevent unbound from executing shell commands, apart from the expected one specified in the `ipsecmod-hook` option.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00067.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00069.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/11/19/1 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-18934 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1776762 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8607 Advisory
- https://github.com/NLnetLabs/unbound/blob/release-1.9.5/doc/Changelog x_refsource_MISCRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MOCR6JP7MSRARTOGEHGST64G4FJGX5VK/ vendor-advisoryx_refsource_FEDORA
- https://nlnetlabs.nl/downloads/unbound/CVE-2019-18934.txt
- https://nvd.nist.gov/vuln/detail/CVE-2019-18934
- https://www.cve.org/CVERecord?id=CVE-2019-18934
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2019-18934.txt x_refsource_MISCPatchVendor Advisory
- https://www.nlnetlabs.nl/news/2019/Nov/19/unbound-1.9.5-released/ x_refsource_CONFIRMRelease NotesVendor Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data