English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Unbound Memory Alignment Denial of Service


Secunia ID

SA38888

CVE-ID

CVE-2010-0969

Release Date

12 Mar 2010

Last Change

17 Mar 2010

Criticality

Moderately Critical

Solution Status

Vendor Patch

Software

Unbound 1.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in Unbound, which can potentially be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a memory alignment error, which can potentially be exploited to cause a crash on 64bit platforms.

The vulnerability is reported in version prior to 1.4.3.

Solution

Update to version 1.4.3.

Reported by

Reported by the vendor.

Original Advisory

http://www.unbound.net/pipermail/unbound-users/2010-March/001057.html