{"id":"MGASA-2021-0154","summary":"Updated unbound packages fix a security vulnerability","details":"Unbound contains a local vulnerability that would allow for a local symlink\nattack. When writing the PID file Unbound creates the file if it is not there,\nor opens an existing file for writing. In case the file was already present, it\nwould follow symlinks if the file happened to be a symlink instead of a regular\nfile (CVE-2020-28935).\n","modified":"2026-04-16T04:42:59.237468248Z","published":"2021-03-27T14:27:02Z","upstream":["CVE-2020-28935"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0154.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28447"},{"type":"WEB","url":"https://www.debian.org/lts/security/2021/dla-2556"}],"affected":[{"package":{"name":"unbound","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/unbound?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.1-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0154.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}