Bugzilla – Bug 1152997
VUL-1: CVE-2019-16866: unbound: Accesses uninitialized memory, triggerd by crafted NOTIFY queries
Last modified: 2019-10-04 22:12:31 UTC
CVE-2019-16866 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. Factory only References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-16866 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16866 http://www.cvedetails.com/cve/CVE-2019-16866/ https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog