Out-of-Bounds Write in Unbound DNS Resolver by NLnet Labs
CVE-2019-25042
9.8CRITICAL
What is CVE-2019-25042?
An issue in Unbound, the DNS resolver by NLnet Labs, earlier than version 1.9.5 allows for an out-of-bounds write through a flaw in the handling of compressed names during the rdata_copy operation. While this behavior is technically concerning, the vendor argues that due to the nature of the code, a running installation of Unbound cannot be remotely or locally exploited, raising questions about the practical implications of this vulnerability.
