HomeFreeBSD

dns/unbound: Uodate to 1.20.0

Description

dns/unbound: Uodate to 1.20.0

ChangeLog: https://nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/

Summary of the DNSBomb vulnerability CVE-2024-33655.
The DNSBomb attack, via specially timed DNS queries and answers, can cause a
Denial of Service on resolvers and spoofed targets.

Unbound itself is not vulnerable for DoS, rather it can be used to take part in
a pulsing DoS amplification attack.

PR: 278870
Reported by: jaap@NLnetLabs.nl (maintainer)
Security: CVE-2024-33655

(cherry picked from commit a478d4b5e7ef58c06031c2e6802dc2a64bd5f4e9)

Details

Provenance
Jaap Akkerhuis <jaap@NLnetLabs.nl>Authored on May 10 2024, 6:37 AM
fernapeCommitted on May 30 2024, 2:00 PM
Parents
R11:c8638b8c2df4: security/py-cryptography-legacy: fix OpenSSL >= 3.0 compat
Branches
Unknown
Tags
Unknown

Event Timeline