Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unbound | Nlnetlabs | * | 1.9.5 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | unbound-0:1.7.3-15.el8 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | unbound-0:1.7.3-12.el8_2 | * |
Unbound | Ubuntu | bionic | * |
Unbound | Ubuntu | focal | * |
Unbound | Ubuntu | trusty | * |
Unbound | Ubuntu | upstream | * |
Unbound | Ubuntu | xenial | * |