CVE-2019-25034: Integer Overflow
DISPUTED Unbound before 1.9.5 allows an integer overflow in sldnsstr2wirednamebuforigin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-25034?
CVE-2019-25034 is an integer overflow vulnerability in Unbound DNS before version 1.9.5.
What is the severity of CVE-2019-25034?
The severity of CVE-2019-25034 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software includes Unbound DNS before version 1.9.5 and Debian Linux version 9.0.
How can CVE-2019-25034 be exploited?
Although the vendor disputes that this is a vulnerability, an attacker may exploit the integer overflow in sldns_str2wire_dname_buf_origin function to trigger an out-of-bounds write.
Are there any references available for CVE-2019-25034?
Yes, you can find references for CVE-2019-25034 at the following links: [link1], [link2], [link3].