CVE-2011-1922 — Reachable Assertion in Unbound
Severity
4.3MEDIUMNVD
EPSS
1.2%
top 20.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 31
Latest updateMay 17
Description
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages2 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2011-1922: unbound - daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and t...↗2011