Project

General

Profile

Actions

Todo #15483

open

Update Unbound to 1.20.0

Added by Glenn Hall 11 days ago. Updated 11 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
DNS Resolver
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
24.07
Release Notes:
Default

Description

Update Unbound to version 1.20.0, as this newest version contains a fix for the DNSBomb vulnerability CVE-2024-33655.

Actions #1

Updated by Jim Pingle 11 days ago

  • Priority changed from Normal-package to Normal
  • Target version set to 2.8.0
  • Plus Target Version set to 24.07

If you read the details that isn't really a vulnerability in Unbound and they only added/changed some default values to make it less of a tempting middleman for attackers. We're already working on updating it, but it's not as critical as if it were a flaw in Unbound itself.

Actions

Also available in: Atom PDF