CVE-2019-25032: Integer Overflow
Published Apr 27, 2021
·Updated
DISPUTED Unbound before 1.9.5 allows an integer overflow in the regional allocator via regionalalloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Affected Software
2 affected components
nlnetlabs Unbound<1.9.5
Debian Debian Linux=9.0
Event History
Apr 27, 2021
CVE Published
via MITRE·05:18 AM
Data Sourced
via MITRE·05:18 AM
Description
Disputed
06:15 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-25032.
2
What is the severity rating of CVE-2019-25032?
CVE-2019-25032 has a severity rating of critical.
3
Which software versions are affected by CVE-2019-25032?
CVE-2019-25032 affects Unbound versions before 1.9.5 and Debian Linux version 9.0.
4
What is the nature of the vulnerability in CVE-2019-25032?
CVE-2019-25032 is an integer overflow vulnerability in the regional allocator of Unbound.
5
Is this vulnerability disputed by the vendor?
Yes, the vendor disputes that this is a vulnerability.