CVE-2019-18934
-
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18934
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with
--enable-ipsecmod
support, and ipsecmod is enabled and used in the configuration.[2.4.4-RELEASE][admin@rutter.in.tern.al]/root: /usr/local/sbin/unbound -v [1576090962] unbound[22309:0] notice: Start of unbound 1.9.1. [2.4.4-RELEASE][admin@rutter.in.tern.al]/root:
So the unbound version in pfSense seems vulnerable. Is pfSense affected? Should I disable the service for the time being?
-
Did you use the search function ?
https://forum.netgate.com/topic/148237/unbound-dns-resolver-vulnerability-in-ipsec-module
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.