The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade unbound to version 1.25.2 or higher.
Affected versions of this package are vulnerable to Data Element containing Pointer Item without Proper Copy Control Element in the process when specific, non-default configurations are enabled, including the use of respip or rpz modules, subquery attachment features, and access-control-view, particularly under heavy server load. An attacker can cause the server to crash by triggering memory corruption through crafted DNS queries. This is only exploitable if the server is configured with the aforementioned modules and features enabled simultaneously under high load conditions.
This vulnerability can be mitigated by disabling the combination of 'respip' or 'rpz' modules, subquery attachment features (such as respip CNAME redirection, dns64, or subnetcache), and 'access-control-view' if not strictly required. Restarting the service after configuration changes is necessary.