Packages
- unbound - validating, recursive, caching DNS resolver
Details
Ralph Dolmans and Karst Koymans discovered that Unbound did not properly
handle certain NSEC records. An attacker could use this to to prove the
non-existence (NXDOMAIN answer) of an existing wildcard record, or trick
Unbound into accepting a NODATA proof.
Ralph Dolmans and Karst Koymans discovered that Unbound did not properly
handle certain NSEC records. An attacker could use this to to prove the
non-existence (NXDOMAIN answer) of an existing wildcard record, or trick
Unbound into accepting a NODATA proof.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
18.04 bionic | libunbound2 – 1.6.7-1ubuntu2.1 | ||
unbound – 1.6.7-1ubuntu2.1 | |||
17.10 artful | libunbound2 – 1.6.5-1ubuntu0.2 | ||
unbound – 1.6.5-1ubuntu0.2 | |||
16.04 xenial | libunbound2 – 1.5.8-1ubuntu1.1 | ||
unbound – 1.5.8-1ubuntu1.1 | |||
14.04 trusty | libunbound2 – 1.4.22-1ubuntu4.14.04.3 | ||
unbound – 1.4.22-1ubuntu4.14.04.3 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.