Integer Overflow Vulnerability in Unbound DNS by NLnet Labs
CVE-2019-25032

9.8CRITICAL

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
27 April 2021

What is CVE-2019-25032?

This vulnerability arises from an integer overflow in the regional allocator within Unbound DNS, impacting versions prior to 1.9.5. Although the vendor disputes its validity as a serious vulnerability, it is crucial to note that this flaw could permit unexpected behaviors in allocation routines. However, the running instances of Unbound cannot be exploited remotely or locally, mitigating concerns about immediate threats. It is vital for users to stay informed about updates and monitor their systems for potential security implications.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.