Unbound DNS Assertion Failure in Versions Prior to 1.9.5 by Netgate
CVE-2019-25041
7.5HIGH
What is CVE-2019-25041?
Unbound versions prior to 1.9.5 are susceptible to an assertion failure due to a compressed name in the dname_pkt_copy function. This vulnerability raises concerns about the stability of the DNS service. However, the vendor asserts that a running Unbound installation cannot be remotely or locally exploited, which may mitigate immediate risks. Security updates are recommended to ensure optimal protection and stability.
