Vulnerability Description
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Unbound | < 1.10.1 |
| Debian | Debian Linux | 9.0 |
| Opensuse | Leap | 15.1 |
| Canonical | Ubuntu Linux | 18.04 |
| Fedoraproject | Fedora | 31 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00067.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00069.htmlMailing ListThird Party Advisory
- http://www.nxnsattack.comTechnical Description
- http://www.openwall.com/lists/oss-security/2020/05/19/5Mailing ListPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00017.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txtVendor Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:19.unbound.ascThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200702-0006/Third Party Advisory
- https://usn.ubuntu.com/4374-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4694Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_12Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00067.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00069.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2020-12662?
CVE-2020-12662 is a vulnerability with a CVSS score of 7.5 (HIGH). Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
How severe is CVE-2020-12662?
CVE-2020-12662 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12662?
Check the references section above for vendor advisories and patch information. Affected products include: Nlnetlabs Unbound, Debian Debian Linux, Opensuse Leap, Canonical Ubuntu Linux, Fedoraproject Fedora.