FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Unbound/NSD -- Denial of service vulnerability

Affected packages
unbound < 1.13.0
nsd < 4.3.4

Details

VuXML ID 388ebb5b-3c95-11eb-929d-d4c9ef517024
Discovery 2020-12-01
Entry 2020-12-12

NLNetLabs reports:

Unbound and NSD when writing the PID file would not check if an existing file was a symlink. This could allow for a local symlink \ attack if an attacker has access to the user Unbound/NSD runs as.

References

CVE Name CVE-2020-28935
URL https://nlnetlabs.nl/downloads/unbound/CVE-2020-28935.txt