MGASA-2018-0091

Source
https://advisories.mageia.org/MGASA-2018-0091.html
Import Source
https://advisories.mageia.org/MGASA-2018-0091.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0091
Related
Published
2018-01-22T21:02:28Z
Modified
2018-01-22T20:49:48Z
Summary
Updated unbound packages fix security vulnerability
Details

Updated unbound packages to fix security vulnerability (CVE-2017-15105) in the processing of wildcard synthesized NSEC records. While synthesis of NSEC records is allowed by RFC4592, these synthesized owner names should not be used in the NSEC processing. This was, however, happenning in Unbound 1.6.7 and earlier versions.

References
Credits

Affected packages

Mageia:6 / unbound

Package

Name
unbound
Purl
pkg:rpm/mageia/unbound?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.8-1.mga6

Ecosystem specific

{
    "section": "core"
}