Integer Overflow Vulnerability in Unbound DNS by NLnet Labs
CVE-2019-25034
9.8CRITICAL
What is CVE-2019-25034?
Unbound DNS, earlier than version 1.9.5, is susceptible to an integer overflow in the function sldns_str2wire_dname_buf_origin, which can result in an out-of-bounds write. While this vulnerability exists in the code, the vendor has disputed its exploitability, clarifying that a running installation of Unbound cannot be exploited, either locally or remotely.
