A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over lo…
High CVSS 8.0
Summary
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogethe…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2024:1750 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1751 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1780 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1801 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1802 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1804 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:2587 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:2696 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0837
- https://access.redhat.com/security/cve/CVE-2024-1488 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2264183 Issue Tracking
- https://access.redhat.com/errata/RHSA-2024:1750 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1751 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1780 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1801 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1802 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1804 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:2587 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:2696 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-1488 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2264183 Issue Tracking
Timeline
- nvd_ingest NVD