Opened 5 months ago
Closed 3 months ago
#23229 closed enhancement (fixed)
unbound-1.25.1 (sysv only)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (7)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|
comment:2 by , 5 months ago
| Summary: | unbound-1.25.0 → unbound-1.25.0 (sysv only) |
|---|
comment:3 by , 5 months ago
| Priority: | normal → high |
|---|---|
| Summary: | unbound-1.25.0 (sysv only) → unbound-1.25.1 (sysv only) |
comment:4 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 5 months ago
Taking this ticket since we haven't heard from Randy and I have a system capable of testing Unbound properly.
comment:6 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at d7ab8e88000c79fc8779381e4ffbef230f17a191. Leaving open for SA.
comment:7 by , 3 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
SA-12.4-113 issued
Note that this is a 12.4 specific advisory as 13.0 does not carry unbound (since 13.0 was systemd only)
Note:
See TracTickets
for help on using tickets.

Now 1.25.1, with a swath of security vulnerability fixes. One of them is rated as Critical due to remote code execution when simply validating DNSSEC responses.