CVE-2024-1488 Information
Feb 16, 2024
cve
Description
A vulnerability was found in Unbound due to incorrect default permissions allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953 it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance potentially altering forwarders allowing them to track all queries forwarded by the local resolver and in some cases disrupting resolving altogether.
Reference
https://access.redhat.com/security/cve/CVE-2024-1488 https://bugzilla.redhat.com/show_bug.cgi?id=2264183
Share on: