cbcvebase.
CVE-2024-1488
published 2024-02-15

CVE-2024-1488: A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime…

high7.3CVSS 3.1
AVLACLPRLUINSUCLIHAH
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
debianunbound
fedoraprojectunbound< 1.19.1-2.fc401.19.1-2.fc40
redhatcodeready_linux_builder
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus_for_power_little_endian
redhatcodeready_linux_builder_eus_for_power_little_endian
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_arm_64_eus