CVE-2019-25033: Integer Overflow
DISPUTED Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGNUP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Other sources
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGNUP macro.
Reference: https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-25033?
CVE-2019-25033 is a vulnerability in Unbound before 1.9.5 that allows an integer overflow in the regional allocator.
What is the severity of CVE-2019-25033?
CVE-2019-25033 has a severity rating of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2019-25033?
Unbound versions prior to 1.9.5 are affected by CVE-2019-25033.
How can CVE-2019-25033 be exploited?
The vendor disputes that CVE-2019-25033 is a vulnerability and states that a running Unbound installation cannot be remotely or locally exploited.
Are there any references for CVE-2019-25033?
Yes, you can find references for CVE-2019-25033 at the following links: [Link 1](https://lists.debian.org/debian-lts-announce/2021/05/msg00007.html), [Link 2](https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/), [Link 3](https://security.netapp.com/advisory/ntap-20210507-0007/).