Severity
7.5HIGHNVD
EPSS
15.5%
top 5.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateMay 24

Description

Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDnlnetlabs/unbound< 1.10.1
Debiannlnetlabs/unbound< 1.10.1-1+3
Ubuntunlnetlabs/unbound< 1.6.7-1ubuntu2.3+1
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, 9.0, Fedora 31, 32, Ubuntu Linux 18.04, 19.10, 20.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-w2pr-2387-vxgh: Unbound before 12022-05-24
OSV
unbound vulnerabilities2020-05-27
CVEList
CVE-2020-12662: Unbound before 12020-05-19
OSV
CVE-2020-12662: Unbound before 12020-05-19

📋Vendor Advisories

6
BSD
FreeBSD-SA-20:19.unbound: Multiple vulnerabilities in unbound2020-07-08
Red Hat
unbound: incomplete fix for CVE-2020-12662 in RHEL72020-06-10
Ubuntu
Unbound vulnerabilities2020-05-27
Red Hat
unbound: amplification of an incoming query into a large number of queries directed to a target2020-05-19
Microsoft
Unbound before 1.10.1 has Insufficient Control of Network Message Volume aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.2020-05-12

💬Community

4
Bugzilla
CVE-2020-10772 unbound: incomplete fix for CVE-2020-12662 in RHEL72020-06-10
Bugzilla
CVE-2020-12662 unbound: amplification of an incoming query into a large number of queries directed to a target [fedora-all]2020-05-19
Bugzilla
CVE-2020-12662 unbound: amplification of an incoming query into a large number of queries directed to a target2020-05-19
Bugzilla
CVE-2020-12663 unbound: infinite loop via malformed DNS answers received from upstream servers2020-05-19
CVE-2020-12662 — Uncontrolled Resource Consumption | cvebase