Vulnerability in the Unbound DNS server allowing remote code execution

In the Unbound DNS server identified vulnerability (CVE-2019-18934), which can lead to the execution of arbitrary code by an attacker upon receiving specially crafted responses. Systems are vulnerable only if Unbound is built with the ipsec module ("--enable-ipsecmod") and ipsecmod is included in the settings. The vulnerability manifests starting from version 1.6.4 and is resolved in the release Unbound 1.9.5.

The vulnerability is caused by the passing of unescaped characters when invoking the shell command ipsecmod-hook, in the case of receiving a request for a domain that has A/AAAA and IPSECKEY records. Code injection is carried out by specifying a specially crafted domain name in the qname and gateway fields associated with the IPSECKEY record.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster