CVE-2019-18934

Published
View on NVD ↗
CVSS v3
7.3
HIGH
CVSS v2
6.8
MEDIUM
Affected
1
PROJECT

Description

Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

Unbound is a validating, recursive, and caching DNS resolver.
GitHubGitHub
4.59K