First published: Tue Apr 27 2021(Updated: )
** DISPUTED ** Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nlnetlabs Unbound | <1.9.5 | |
Debian Debian Linux | =9.0 | |
<1.9.5 | ||
=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-25031.
The severity of CVE-2019-25031 is medium (5.9).
Unbound before version 1.9.5 and Debian Linux version 9.0 are affected by CVE-2019-25031.
The vulnerability allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session.
No, the vendor does not consider CVE-2019-25031 a vulnerability of the Unbound software.