UbuntuUpdates.org

Package "python-unbound"

Name: python-unbound

Description:

library implementing DNS resolution and validation (Python bindings)

Latest version: 1.6.7-1ubuntu2.6
Release: bionic (18.04)
Level: security
Repository: universe
Head package: unbound
Homepage: https://www.unbound.net/

Links


Download "python-unbound"


Other versions of "python-unbound" in Bionic

Repository Area Version
base universe 1.6.7-1ubuntu2
updates universe 1.6.7-1ubuntu2.6

Changelog

Version: 1.6.7-1ubuntu2.6 2022-11-17 20:06:27 UTC

  unbound (1.6.7-1ubuntu2.6) bionic-security; urgency=medium

  * SECURITY UPDATE: Non-Responsive Delegation Attack
    - debian/patches/CVE-2022-3204.patch: limit number of lookups in
      iterator/iter_delegpt.*, iterator/iter_utils.*, iterator/iterator.c,
      services/cache/dns.c, services/mesh.*.
    - CVE-2022-3204

 -- Marc Deslauriers <email address hidden> Tue, 15 Nov 2022 15:07:17 -0500

Source diff to previous version
CVE-2022-3204 A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegatio

Version: 1.6.7-1ubuntu2.5 2022-08-16 15:06:18 UTC

  unbound (1.6.7-1ubuntu2.5) bionic-security; urgency=medium

  * SECURITY UPDATE: Ghost domain names issues
    - debian/patches/CVE-2022-3069x-pre1.patch: fix that cachedb could
      return a partial CNAME chain in cachedb/cachedb.c,
      iterator/iterator.c, services/cache/dns.c, services/cache/dns.h.
    - debian/patches/CVE-2022-3069x-pre2.patch: backport a version of the
      iter_stub_fwd_no_cache function in iterator/iter_utils.c,
      iterator/iter_utils.h.
    - debian/patches/CVE-2022-3069x-pre3.patch: fix that nxdomain synthesis
      does not happen above the stub or forward definition in
      cachedb/cachedb.c, iterator/iter_utils.c, iterator/iter_utils.h,
      iterator/iterator.c, services/cache/dns.c, services/cache/dns.h.
    - debian/patches/CVE-2022-3069x.patch: fix the novel ghost domain
      issues in cachedb/cachedb.c, daemon/cachedump.c, daemon/worker.c,
      dns64/dns64.c, ipsecmod/ipsecmod.c, iterator/iter_utils.c,
      iterator/iter_utils.h, iterator/iterator.c, pythonmod/interface.i,
      pythonmod/pythonmod_utils.c, services/cache/dns.c,
      services/cache/dns.h, services/mesh.c,
      testdata/iter_prefetch_change.rpl, util/module.h,
      validator/validator.c.
    - CVE-2022-30698
    - CVE-2022-30699

 -- Marc Deslauriers <email address hidden> Thu, 04 Aug 2022 07:56:04 -0400

Source diff to previous version
CVE-2022-30698 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by t
CVE-2022-30699 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by

Version: 1.6.7-1ubuntu2.4 2021-05-06 14:07:18 UTC

  unbound (1.6.7-1ubuntu2.4) bionic-security; urgency=medium

  * SECURITY UPDATE: configuration injection via MITM
    - debian/patches/CVE-2019-25031.patch: use https, remove special
      characters in contrib/create_unbound_ad_servers.sh.
    - CVE-2019-25031
  * SECURITY UPDATE: integer overflows in the regional allocator
    - debian/patches/CVE-2019-25032.patch: fix overflows in config.h.in,
      configure, configure.ac, util/regional.c.
    - CVE-2019-25032
    - CVE-2019-25033
  * SECURITY UPDATE: integer overflow in sldns_str2wire_dname_buf_origin
    - debian/patches/CVE-2019-25034.patch: check lengths in
      sldns/str2wire.c.
    - CVE-2019-25034
  * SECURITY UPDATE: out-of-bounds write in sldns_bget_token_par
    - debian/patches/CVE-2019-25035.patch: check for space in
      sldns/parse.c.
    - CVE-2019-25035
  * SECURITY UPDATE: assertion failure and denial of service
    - debian/patches/CVE-2019-25036.patch: validate lengths in
      iterator/iter_scrub.c.
    - CVE-2019-25036
  * SECURITY UPDATE: assertion failure and denial of service
    - debian/patches/CVE-2019-25037.patch: validate length in
      util/data/dname.c.
    - CVE-2019-25037
  * SECURITY UPDATE: integer overflow in a size calculation
    - debian/patches/CVE-2019-25038.patch: check for overflows in
      dnscrypt/dnscrypt.c, respip/respip.c.
    - CVE-2019-25038
    - CVE-2019-25039
  * SECURITY UPDATE: infinite loop and assertion fail via compressed name
    - debian/patches/CVE-2019-25040.patch: validate compression pointers in
      util/data/dname.c.
    - CVE-2019-25040
    - CVE-2019-25041
  * SECURITY UPDATE: out-of-bounds write via a compressed name
    - debian/patches/CVE-2019-25042.patch: move assert in
      util/data/msgreply.c.
    - CVE-2019-25042
  * SECURITY UPDATE: incorrect PID file handling
    - debian/patches/CVE-2020-28935.patch: check for symlinks in
      daemon/unbound.c.
    - CVE-2020-28935
  * debian/patches: rename debian-changes to misc-changes.patch.

 -- Marc Deslauriers <email address hidden> Wed, 05 May 2021 07:38:50 -0400

Source diff to previous version
CVE-2019-25031 Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT
CVE-2019-25032 Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc.
CVE-2019-25033 Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro.
CVE-2019-25034 Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write.
CVE-2019-25035 Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par.
CVE-2019-25036 Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname.
CVE-2019-25037 Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet.
CVE-2019-25038 Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c.
CVE-2019-25039 Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c.
CVE-2019-25040 Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy.
CVE-2019-25041 Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy.
CVE-2019-25042 Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy.
CVE-2020-28935 NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou

Version: 1.6.7-1ubuntu2.3 2020-05-27 20:06:48 UTC

  unbound (1.6.7-1ubuntu2.3) bionic-security; urgency=medium

  * SECURITY UPDATE: amplification attack and denial of service
    - debian/patches/CVE-2020-1226x.patch: fix iterator logic in
      iterator/iter_delegpt.c, iterator/iter_delegpt.h,
      iterator/iter_scrub.c, iterator/iter_utils.c, iterator/iterator.c,
      iterator/iterator.h, services/cache/dns.c, util/data/dname.c,
      util/data/msgparse.c.
    - CVE-2020-12263
    - CVE-2020-12264

 -- Marc Deslauriers <email address hidden> Fri, 22 May 2020 09:11:45 -0400

Source diff to previous version
CVE-2020-1226 RESERVED
CVE-2020-12263 RESERVED
CVE-2020-12264 RESERVED

Version: 1.6.7-1ubuntu2.1 2018-06-08 00:06:57 UTC

  unbound (1.6.7-1ubuntu2.1) bionic-security; urgency=medium

  * SECURITY UPDATE: vulnerability in the processing of wildcard
    synthesized NSEC records (LP: #1773720)
    - debian/patches/CVE-2017-15105.patch
    - CVE-2017-15105

 -- Simon Deziel <email address hidden> Mon, 28 May 2018 02:38:19 +0000

1773720 CVE-2017-15105
CVE-2017-15105 A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u



About   -   Send Feedback to @ubuntu_updates