Infinite Loop Vulnerability in Unbound DNS Resolver by NLnet Labs
CVE-2019-25040

7.5HIGH

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
27 April 2021

What is CVE-2019-25040?

Unbound DNS Resolver prior to version 1.9.5 is susceptible to an infinite loop triggered by a specially crafted compressed name in the dname_pkt_copy function. Although the vendor contests that this poses a security risk, it's important to note that, under normal operating conditions, the affected Unbound installations cannot be exploited both locally or remotely. Administrators should ensure their installations are updated to mitigate potential issues.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.