RULE(RULE ID:105326)

Rule General Information
Release Date: 2020-08-24
Rule Name: NLnet Labs Unbound NOTIFY Queries Denial of Service Vulnerability (CVE-2019-16866)
Severity:
CVE ID:
Rule Protection Details
Description: Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Others
Reference: https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/
https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog