Vulnerability Name: | CVE-2019-16866 (CCN-168591) | ||||||||||||||||||||||||
Assigned: | 2019-09-25 | ||||||||||||||||||||||||
Published: | 2019-09-25 | ||||||||||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||||||||||
Summary: | Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-755 CWE-908 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-16866 Source: XF Type: UNKNOWN unbound-cve201916866-dos(168591) Source: CCN Type: Unbound GIT Repository Unbound Source: MISC Type: Product, Release Notes https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog Source: FEDORA Type: UNKNOWN FEDORA-2019-e99b716a92 Source: FEDORA Type: UNKNOWN FEDORA-2019-0418c12a36 Source: MISC Type: Patch, Vendor Advisory https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt Source: BUGTRAQ Type: UNKNOWN 20191016 [SECURITY] [DSA 4544-1] unbound security update Source: UBUNTU Type: Third Party Advisory USN-4149-1 Source: DEBIAN Type: UNKNOWN DSA-4544 Source: CCN Type: IBM Security Bulletin 6214488 (Vyatta 5600) Vyatta 5600 vRouter Software Patches - Release 1801-ze Source: CCN Type: IBM Security Bulletin 6853463 (Robotic Process Automation for Cloud Pak) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |