CVE-2019-25035: Critical severity unbound vulnerability
Published Apr 27, 2021
·Updated
DISPUTED Unbound before 1.9.5 allows an out-of-bounds write in sldnsbgettokenpar. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Affected Software
2 affected components
nlnetlabs Unbound<1.9.5
Debian Debian Linux=9.0
Event History
Apr 27, 2021
CVE Published
via MITRE·05:17 AM
Data Sourced
via MITRE·05:17 AM
Description
Disputed
06:15 AM
Frequently Asked Questions
1
What is CVE-2019-25035?
CVE-2019-25035 is a vulnerability in the Unbound DNS resolver before version 1.9.5.
2
What is the severity of CVE-2019-25035?
CVE-2019-25035 has a severity rating of 9.8, which is considered critical.
3
Which software is affected by CVE-2019-25035?
Unbound DNS resolver versions before 1.9.5 are affected by CVE-2019-25035.
4
How can CVE-2019-25035 be exploited?
While the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
5
Is CVE-2019-25035 disputed by the vendor?
Yes, the vendor disputes that CVE-2019-25035 is a vulnerability.