Integer Overflow in Unbound DNS Resolver by NLnet Labs
CVE-2019-25038
9.8CRITICAL
What is CVE-2019-25038?
An integer overflow vulnerability exists in the size calculation in the dnscrypt/dnscrypt.c file of Unbound versions prior to 1.9.5. Although the vendor asserts that this issue is not an actual vulnerability, the code structure suggests potential risks. Importantly, a running Unbound installation is not vulnerable to remote or local exploitation, mitigating concerns regarding immediate threat levels. Users are encouraged to keep their software updated to prevent any unforeseen circumstances.
