CVE-2019-25039: Integer Overflow
Published Apr 27, 2021
·Updated
DISPUTED Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Affected Software
2 affected components
nlnetlabs Unbound<1.9.5
Debian Debian Linux=9.0
Remediation
Event History
Apr 27, 2021
CVE Published
via MITRE·05:16 AM
Data Sourced
via MITRE·05:16 AM
Description
Disputed
06:15 AM
Frequently Asked Questions
1
What is CVE-2019-25039?
CVE-2019-25039 is a vulnerability in Unbound DNS server before version 1.9.5.
2
What is the severity of CVE-2019-25039?
CVE-2019-25039 has a severity rating of 9.8 (Critical).
3
How does CVE-2019-25039 affect Unbound DNS server?
CVE-2019-25039 allows an integer overflow in a size calculation in respip/respip.c, potentially leading to remote or local exploitation.
4
Is CVE-2019-25039 actively being exploited?
There is no known active exploitation of CVE-2019-25039 reported at this time.
5
How can I fix CVE-2019-25039 in Unbound DNS server?
To fix CVE-2019-25039, it is recommended to update Unbound DNS server to version 1.9.5 or later.