Vulnerabilities > CVE-2024-1488

047910
CVSS 7.3 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
fedoraproject
redhat

Summary

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

Vulnerable Configurations

Part Description Count
Application
Fedoraproject
1
Application
Redhat
11
OS
Redhat
39