SUSE SLED15 / SLES15 Security Update : unbound (SUSE-SU-2022:0176-1)

critical Nessus Plugin ID 157078

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:0176-1 advisory.

- CVE-2019-25031: Fixed configuration injection in create_unbound_ad_servers.sh upon a successful man-in- the-middle attack (bsc#1185382).
- CVE-2019-25032: Fixed integer overflow in the regional allocator via regional_alloc (bsc#1185383).
- CVE-2019-25033: Fixed integer overflow in the regional allocator via the ALIGN_UP macro (bsc#1185384).
- CVE-2019-25034: Fixed integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write (bsc#1185385).
- CVE-2019-25035: Fixed out-of-bounds write in sldns_bget_token_par (bsc#1185386).
- CVE-2019-25036: Fixed assertion failure and denial of service in synth_cname (bsc#1185387).
- CVE-2019-25037: Fixed assertion failure and denial of service in dname_pkt_copy via an invalid packet (bsc#1185388).
- CVE-2019-25038: Fixed integer overflow in a size calculation in dnscrypt/dnscrypt.c (bsc#1185389).
- CVE-2019-25039: Fixed integer overflow in a size calculation in respip/respip.c (bsc#1185390).
- CVE-2019-25040: Fixed infinite loop via a compressed name in dname_pkt_copy (bsc#1185391).
- CVE-2019-25041: Fixed assertion failure via a compressed name in dname_pkt_copy (bsc#1185392).
- CVE-2019-25042: Fixed out-of-bounds write via a compressed name in rdata_copy (bsc#1185393).
- CVE-2020-28935: Fixed symbolic link traversal when writing PID file (bsc#1179191).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected libunbound2, unbound-anchor and / or unbound-devel packages.

See Also

https://bugzilla.suse.com/1076963

https://bugzilla.suse.com/1112009

https://bugzilla.suse.com/1112033

https://bugzilla.suse.com/1179191

https://bugzilla.suse.com/1185382

https://bugzilla.suse.com/1185383

https://bugzilla.suse.com/1185384

https://bugzilla.suse.com/1185385

https://bugzilla.suse.com/1185386

https://bugzilla.suse.com/1185387

https://bugzilla.suse.com/1185388

https://bugzilla.suse.com/1185389

https://bugzilla.suse.com/1185390

https://bugzilla.suse.com/1185391

https://bugzilla.suse.com/1185392

https://bugzilla.suse.com/1185393

https://www.suse.com/security/cve/CVE-2019-25031

https://www.suse.com/security/cve/CVE-2019-25032

https://www.suse.com/security/cve/CVE-2019-25033

https://www.suse.com/security/cve/CVE-2019-25034

https://www.suse.com/security/cve/CVE-2019-25035

https://www.suse.com/security/cve/CVE-2019-25036

https://www.suse.com/security/cve/CVE-2019-25037

https://www.suse.com/security/cve/CVE-2019-25038

https://www.suse.com/security/cve/CVE-2019-25039

https://www.suse.com/security/cve/CVE-2019-25040

https://www.suse.com/security/cve/CVE-2019-25041

https://www.suse.com/security/cve/CVE-2019-25042

https://www.suse.com/security/cve/CVE-2020-28935

http://www.nessus.org/u?1900b34a

Plugin Details

Severity: Critical

ID: 157078

File Name: suse_SU-2022-0176-1.nasl

Version: 1.6

Type: Local

Agent: unix

Published: 1/26/2022

Updated: 6/26/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, tenable_cloud_security, tenable_self_hosted_container_security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-25042

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:unbound-devel, p-cpe:/a:novell:suse_linux:libunbound2, p-cpe:/a:novell:suse_linux:unbound-anchor, cpe:/o:novell:suse_linux:15

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 1/25/2022

Vulnerability Publication Date: 12/7/2020

Reference Information

CVE: CVE-2019-25031, CVE-2019-25032, CVE-2019-25033, CVE-2019-25034, CVE-2019-25035, CVE-2019-25036, CVE-2019-25037, CVE-2019-25038, CVE-2019-25039, CVE-2019-25040, CVE-2019-25041, CVE-2019-25042, CVE-2020-28935

SuSE: SUSE-SU-2022:0176-1