]> git.ipfire.org Git - thirdparty/unbound.git/commit
- CVE-2020-12662 Unbound can be tricked into amplifying an incoming
authorW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Tue, 19 May 2020 08:27:27 +0000 (10:27 +0200)
committerW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Tue, 19 May 2020 08:27:27 +0000 (10:27 +0200)
commitba0f382eee814e56900a535778d13206b86b6d49
treeb697c7e66cafc9df2d91bd0efaed4503203cb25e
parent4ccac696caf8826995c9db78af6074a5a1381f00
- CVE-2020-12662 Unbound can be tricked into amplifying an incoming
  query into a large number of queries directed to a target.
- CVE-2020-12663 Malformed answers from upstream name servers can be
  used to make Unbound unresponsive.
doc/Changelog
iterator/iter_delegpt.c
iterator/iter_delegpt.h
iterator/iter_scrub.c
iterator/iter_utils.c
iterator/iterator.c
iterator/iterator.h
services/cache/dns.c
util/data/dname.c
util/data/msgparse.c