RE: CVE 2024 1931 - unbound
"Wall, Stephen" <[email protected]> Mon, 8 Jul 2024 18:08:16 +0000
| Newsgroups | gmane.os.freebsd.security.general |
|---|---|
| Message-ID | <MW4PR09MB9284B0E97E41A1B660DF2632EEDA2@MW4PR09MB9284.namprd09.prod.outlook.com> |
> > > a prerequisite for the DoS attack described in CVE-2024-1931. > Did you actually mean CVE-2024-33655 instead? I mean CVE-2024-1931, in which unbound is vulnerable to a DoS if 'ede: yes' is configured. This is fixed in unbound 1.19.2, but 14.0 uses 1.19.1.