ELSA-2020-2640

ELSA-2020-2640 - unbound security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2020-06-23

Description


[1.4.20-29.1]
- Fix segfault in unbound-1.4.20-amplifying-an-incoming-query.patch
- Resolves: rhbz#1839171 (CVE-2020-12662), rhbz#1840257 (CVE-2020-12663)

[1.4.20-28.1]
- Fix unbound-1.4.20-amplifying-an-incoming-query.patch patch so it won't produce compiler warnings
- Resolves: rhbz#1839171 (CVE-2020-12662), rhbz#1840257 (CVE-2020-12663)

[1.4.20-27.1]
- Fix amplifying an incoming query into a large number of queries directed to a target
- Resolves: rhbz#1839171 (CVE-2020-12662), rhbz#1840257 (CVE-2020-12663)

[1.4.20-26.1]
- Resolves: #1655929 - Unbound crashed when running 'unbound-control log_reopen'


Related CVEs


CVE-2020-12662
CVE-2020-12663

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) unbound-1.4.20-29.el6_10.1.src.rpmedaec44370f4d9858e2724a154540473-
unbound-1.4.20-29.el6_10.1.i686.rpme08c183a79f3299cba1c52d743fefb8f-
unbound-devel-1.4.20-29.el6_10.1.i686.rpm327e6c32b80412d35bd1f59b92f45928-
unbound-libs-1.4.20-29.el6_10.1.i686.rpmfd3145155414db9cc2c3cd95ed20cee8-
unbound-python-1.4.20-29.el6_10.1.i686.rpmef7c979e658745eaca04fcc040f709d1-
Oracle Linux 6 (x86_64) unbound-1.4.20-29.el6_10.1.src.rpmedaec44370f4d9858e2724a154540473-
unbound-1.4.20-29.el6_10.1.x86_64.rpm375eea6f7096c469749226bb73190aae-
unbound-devel-1.4.20-29.el6_10.1.i686.rpm327e6c32b80412d35bd1f59b92f45928-
unbound-devel-1.4.20-29.el6_10.1.x86_64.rpmf84ac6e96ab8b10fbe2edad2bacddd7f-
unbound-libs-1.4.20-29.el6_10.1.i686.rpmfd3145155414db9cc2c3cd95ed20cee8-
unbound-libs-1.4.20-29.el6_10.1.x86_64.rpm4b47dca9259149510b06eede5d0f42aa-
unbound-python-1.4.20-29.el6_10.1.i686.rpmef7c979e658745eaca04fcc040f709d1-
unbound-python-1.4.20-29.el6_10.1.x86_64.rpm4d66f9e385e267f6e177c92f7d826ca7-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete