CVE-2011-1922Reachable Assertion in Unbound

CWE-3999 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
1.2%
top 20.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 31
Latest updateMay 17

Description

daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debiannlnetlabs/unbound< 1.4.10-1+3
NVDnlnetlabs/unbound22 versions+21

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gcr6-mhvm-c5mf: daemon/worker2022-05-17
OSV
CVE-2011-1922: daemon/worker2011-05-31
CVEList
CVE-2011-1922: daemon/worker2011-05-31

📋Vendor Advisories

1
Debian
CVE-2011-1922: unbound - daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and t...2011

💬Community

4
Bugzilla
CVE-2011-1922 unbound: remote DoS [fedora-all]2011-05-31
Bugzilla
CVE-2011-1922 unbound: remote DoS [epel-6]2011-05-31
Bugzilla
CVE-2011-1922 unbound: remote DoS [epel-5]2011-05-31
Bugzilla
CVE-2011-1922 unbound: remote DoS2011-05-31
CVE-2011-1922 — Reachable Assertion in Unbound | cvebase