← Back

CVE-2024-1488

nvd nist
Published: Feb 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Exploitability: 1.8 / Impact: 5.5
Source: NVD

Description

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

Affected (51)

1 product
Unbound
18 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.19.1-2.fc40
Configuration B
50 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Redhat
Version 9.2
Version 9.4
Redhat
Version 9.0_ppc64le
Version 9.2_ppc64le
Redhat
Version 9.0_aarch64
Version 9.2_aarch64
Version 9.4_aarch64
Redhat
Version 9.0_s390x
Version 9.2_s390x
Version 9.4_s390x
Redhat
Version 8.0
Version 9.0
Redhat
Version 8.6
Version 8.8
Version 9.2
Version 9.4
Redhat
Version 8.0_aarch64
Version 9.0_aarch64
Version 9.2_aarch64
Redhat
Version 8.6_aarch64
Version 8.8_aarch64
Version 9.4_aarch64
Redhat
Version 8.0_s390x
Version 9.0_s390x
Version 9.2_s390x
Redhat
Version 8.6_s390x
Version 8.8_s390x
Version 9.4_s390x
Redhat
Version 8.0_ppc64le
Version 9.0_ppc64le
Version 9.2_ppc64le
Redhat
Version 8.6_ppc64le
Version 8.8_ppc64le
Version 9.4_ppc64le
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 9.2
Version 9.4
Redhat
Version 8.2_ppc64le
Version 8.4_ppc64le
Version 8.6_ppc64le
Version 8.8_ppc64le
Version 9.2_ppc64le
Version 9.4_ppc64le
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 8.8

References (21)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch

Timeline

No history available yet.