-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4694-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 26, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : unbound CVE ID : CVE-2020-12662 CVE-2020-12663 Two vulnerabiliites have been discovered in Unbound, a recursive-only caching DNS server; a traffic amplification attack against third party authoritative name servers (NXNSAttack) and insufficient sanitisation of replies from upstream servers could result in denial of service via an infinite loop. The version of Unbound in the oldstable distribution (stretch) is no longer supported. If these security issues affect your setup, you should upgrade to the stable distribution (buster). For the stable distribution (buster), these problems have been fixed in version 1.9.0-2+deb10u2. We recommend that you upgrade your unbound packages. For the detailed security status of unbound please refer to its security tracker page at: https://security-tracker.debian.org/tracker/unbound Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl7NiOIACgkQEMKTtsN8 TjZ/9BAAt5M24/ptZACrxestREWO5ybtVWdzn0ffROyd+Rw+8A+C1Zb+lJBZt1dV xxAqO0aW4JYeYdhhZMwVR/nu9csTVMg6k6oEdd4tmqlJwtX4ke9DsU9KmtmREvfO nW4Mab1fldFqSO1bp3jzbyLoozZgBO791CKKPRBAn6ewvOaL4QmljmJgLA0l8oYV O0ab2jI1iC86hll7Av0m6HFbqkvaBBpTdgHatkZjQEd3hUh57BbQOFm4AYuaUj09 x3vVtD1AzLA4R7DbwnE7c7ngflxD4wbRXdMjyjcLWWj+jPMvZ/aoP1xHyb13WLg7 iT9dX8/0H6yiT+VQg8zjwBynBUdq8PnhDLBBDfV7VcXwZsC8dQhtx/k0KYpL6w1J eJ4kvyp3Ub7XnoK8frimuE3/K87aLTlbuY+7yr1fYjtz8jI+u/caG2/N0F8coT6c v+PUJX12XNlxnJsSVS07VSbsyWYaRi63bupiN+bOmvWm7uW3uFU8n+NDlioorTor Mf47id1ijb3GWOz1fcUZC8s3a7m0cOkbyBAHMDWloK6/jWFw50MxOKDVR3Ky1unp 1nxQWbhWNaca4Kwtg1vdDeOf+gr+SbI0YER3jOtseFx7xK53HRC/1y8ecdft9ofJ JuarPZEQLZX9OfrBd3NfqYTIVrKTJ3p/zlkjnHRR5vNRuRXVpXM= =p2bf -----END PGP SIGNATURE-----