Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unbound | Nlnetlabs | * | 1.9.4 (excluding) |
Unbound | Ubuntu | devel | * |
Unbound | Ubuntu | disco | * |
Unbound | Ubuntu | trusty | * |