Out-of-Bounds Write in Unbound DNS Resolver by NLnet Labs
CVE-2019-25042

9.8CRITICAL

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
27 April 2021

What is CVE-2019-25042?

An issue in Unbound, the DNS resolver by NLnet Labs, earlier than version 1.9.5 allows for an out-of-bounds write through a flaw in the handling of compressed names during the rdata_copy operation. While this behavior is technically concerning, the vendor argues that due to the nature of the code, a running installation of Unbound cannot be remotely or locally exploited, raising questions about the practical implications of this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.