7.3
CVE-2024-1488
- EPSS 0.32%
- Veröffentlicht 15.02.2024 05:15:10
- Zuletzt bearbeitet 06.08.2026 22:16:39
- Erkennungen
Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Unbound Version < 1.19.1-2.fc40
Redhat ≫ Codeready Linux Builder Version 9.0
Redhat ≫ Codeready Linux Builder Eus Version 9.2
Redhat ≫ Codeready Linux Builder Eus Version 9.4
Redhat ≫ Codeready Linux Builder Eus For Power Little Endian Version 9.0_ppc64le
Redhat ≫ Codeready Linux Builder Eus For Power Little Endian Version 9.2_ppc64le
Redhat ≫ Codeready Linux Builder For Arm64 Version 9.0_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Version 9.2_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 9.4_aarch64
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Version 9.0_s390x
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Version 9.2_s390x
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 9.4_s390x
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.8
Redhat ≫ Enterprise Linux Eus Version 9.2
Redhat ≫ Enterprise Linux Eus Version 9.4
Redhat ≫ Enterprise Linux For Arm 64 Version 8.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.2_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.6_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.8_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.6_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.8_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.4_s390x
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Version 9.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Version 9.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.6_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.8_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.4_ppc64le
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.6
Redhat ≫ Enterprise Linux Server Aus Version 9.2
Redhat ≫ Enterprise Linux Server Aus Version 9.4
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.2_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.4_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.6_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.8_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.2_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.4_ppc64le
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.6
Redhat ≫ Enterprise Linux Server Tus Version 8.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.249 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.3 | 1.8 | 5.5 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
|
| RedHat | 8 | 2.5 | 5.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
https://bugzilla.redhat.com/show_bug.cgi?id=2264183
https://access.redhat.com/errata/RHSA-2024:1750
https://access.redhat.com/errata/RHSA-2024:1751
https://access.redhat.com/errata/RHSA-2024:1780
https://access.redhat.com/errata/RHSA-2024:1801
https://access.redhat.com/errata/RHSA-2024:1802
https://access.redhat.com/errata/RHSA-2024:1804
https://access.redhat.com/errata/RHSA-2024:2587
https://access.redhat.com/errata/RHSA-2024:2696
https://access.redhat.com/errata/RHSA-2025:0837
https://access.redhat.com/security/cve/CVE-2024-1488