UbuntuUpdates.org

Package "libunbound8"

Name: libunbound8

Description:

library implementing DNS resolution and validation

Latest version: 1.13.1-1ubuntu5.8
Release: jammy (22.04)
Level: security
Repository: main
Head package: unbound
Homepage: https://www.unbound.net/

Links


Download "libunbound8"


Other versions of "libunbound8" in Jammy

Repository Area Version
base main 1.13.1-1ubuntu5
updates main 1.13.1-1ubuntu5.8

Changelog

Version: 1.13.1-1ubuntu5.1 2022-08-16 15:06:22 UTC

  unbound (1.13.1-1ubuntu5.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Ghost domain names issues
    - debian/patches/CVE-2022-3069x-pre1.patch: fix that nxdomain synthesis
      does not happen above the stub or forward definition in
      cachedb/cachedb.c, edns-subnet/subnetmod.c, iterator/iter_utils.c,
      iterator/iter_utils.h, iterator/iterator.c, services/cache/dns.c,
      services/cache/dns.h.
    - debian/patches/CVE-2022-3069x.patch: fix the novel ghost domain
      issues in cachedb/cachedb.c, daemon/cachedump.c, daemon/worker.c,
      dns64/dns64.c, ipsecmod/ipsecmod.c, iterator/iter_utils.c,
      iterator/iter_utils.h, iterator/iterator.c, pythonmod/interface.i,
      pythonmod/pythonmod_utils.c, services/cache/dns.c,
      services/cache/dns.h, services/mesh.c,
      testdata/iter_prefetch_change.rpl, util/module.h,
      validator/validator.c.
    - CVE-2022-30698
    - CVE-2022-30699

 -- Marc Deslauriers <email address hidden> Tue, 02 Aug 2022 09:52:58 -0400

CVE-2022-30698 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by t
CVE-2022-30699 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by



About   -   Send Feedback to @ubuntu_updates