QID 352454

Date Published: 2021-07-02

QID 352454: Amazon Linux Security Advisory for unbound: ALAS2-2021-1683

<DIV ID="issue_overview"> a flaw was found in unbound.
An integer overflow in regional_alloc function may lead to a buffer overflow of the allocated buffer if the size can be controlled by an attacker and can be big enough.
The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability. (
cve-2019-25032 ) a flaw was found in unbound.
An integer overflow in the sldns_str2wire_dname_buf_origin function may lead to a buffer overflow.
cve-2019-25034 ) a flaw was found in unbound.
An out-of-bounds write in the sldns_bget_token_par function may be abused by a remote attacker.
cve-2019-25035 ) a flaw was found in unbound.
A reachable assertion in the synth_cname function can be triggered by sending invalid packets to the server.
If asserts are disabled during compilation, this issue might lead to an out-of-bounds write in dname_pkt_copy function.
cve-2019-25036 ) a flaw was found in unbound.
A reachable assertion in the dname_pkt_copy function can be triggered by sending invalid packets to the server.
The highest threat from this vulnerability is to service availability. (
cve-2019-25037 ) a flaw was found in unbound.
An integer overflow in dnsc_load_local_data function may lead to a buffer overflow of the allocated buffer if the size can be controlled by an attacker.
cve-2019-25038 ) a flaw was found in unbound.
An integer overflow in ub_packed_rrset_key function may lead to a buffer overflow of the allocated buffer if the size can be controlled by an attacker.
cve-2019-25039 ) a flaw was found in unbound.
An infinite loop in dname_pkt_copy function could be triggered by a remote attacker.
cve-2019-25040 ) a flaw was found in unbound.
A reachable assertion in the dname_pkt_copy function can be triggered through compressed names.
cve-2019-25041 ) a flaw was found in unbound.
An out-of-bounds write in the rdata_copy function may be abused by a remote attacker.
cve-2019-25042 ) nlnet labs unbound, up to and including version 1.12.0, and nlnet labs nsd, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack.
When writing the pid file, unbound and nsd create the file if it is not there, or open an existing file for writing.
In case the file was already present, they would follow symlinks if the file happened to be a symlink instead of a regular file.
An additional chown of the file would then take place after it was written, making the user unbound/nsd is supposed to run as the new owner of the file.
If an attacker has local access to the user unbound/nsd runs as, she could create a symlink in place of the pid file pointing to a file that she would like to erase.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2-2021-1683 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2-2021-1683 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1683.html