A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.1-2.fc40"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.4_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1488.json"