CVE-2024-1488
published 2024-02-15CVE-2024-1488: A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime…
PriorityP341high7.3CVSS 3.1
AVLACLPRLUINSUCLIHAH
EPSS
0.32%
23.9th percentile
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | unbound | — | — |
| fedoraproject | unbound | < 1.19.1-2.fc40 | 1.19.1-2.fc40 |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_eus_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
vendor_debian8.0LOW
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
vendor_redhat·2024-02-13·CVSS 8.0
CVE-2024-1488 [HIGH] CWE-276 unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over
Debian
CVE-2024-1488: unbound - A vulnerability was found in Unbound due to incorrect default permissions, allow...
vendor_debian·2024·CVSS 8.0
CVE-2024-1488 [HIGH] CVE-2024-1488: unbound - A vulnerability was found in Unbound due to incorrect default permissions, allow...
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
ghsa·2024-12-02
CVE-2024-52800 [LOW] CWE-611 veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
### Impact
Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability.
### Patches
We are currently working on a patch that will be released when ready.
### Workarounds
This doesn't affect the standard validation and policy checks functionality, veraPDF's common use cases. Most veraPDF users don't insert any custom XSLT code into policy profiles, which are based on Schematron syntax rather than direct XSL transforms. For users who do, only load custom policy files from sources you trust.
### References
Original issue: #1488
GHSA
GHSA-35qh-7f6c-rjf7: A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtim
ghsa_unreviewed·2024-02-15
CVE-2024-1488 [HIGH] CWE-15 GHSA-35qh-7f6c-rjf7: A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtim
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
Suricata
GPL EXPLOIT .htr access
suricata·2010-09-23
CVE-2000-0630 GPL EXPLOIT .htr access
GPL EXPLOIT .htr access
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT .htr access"; flow:established,to_server; http.uri; content:".htr"; nocase; reference:bugtraq,1488; reference:cve,2000-0630; reference:nessus,10680; classtype:web-application-activity; sid:2100987; rev:18; metadata:created_at 2010_09_23, cve CVE_2000_0630, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:1750https://access.redhat.com/errata/RHSA-2024:1751https://access.redhat.com/errata/RHSA-2024:1780https://access.redhat.com/errata/RHSA-2024:1801https://access.redhat.com/errata/RHSA-2024:1802https://access.redhat.com/errata/RHSA-2024:1804https://access.redhat.com/errata/RHSA-2024:2587https://access.redhat.com/errata/RHSA-2024:2696https://access.redhat.com/errata/RHSA-2025:0837https://access.redhat.com/security/cve/CVE-2024-1488https://bugzilla.redhat.com/show_bug.cgi?id=2264183https://access.redhat.com/errata/RHSA-2024:1750https://access.redhat.com/errata/RHSA-2024:1751https://access.redhat.com/errata/RHSA-2024:1780https://access.redhat.com/errata/RHSA-2024:1801https://access.redhat.com/errata/RHSA-2024:1802https://access.redhat.com/errata/RHSA-2024:1804https://access.redhat.com/errata/RHSA-2024:2587https://access.redhat.com/errata/RHSA-2024:2696https://access.redhat.com/security/cve/CVE-2024-1488https://bugzilla.redhat.com/show_bug.cgi?id=2264183
2024-02-15
Published