CVE-2019-25040: High severity unbound vulnerability
DISPUTED Unbound before 1.9.5 allows an infinite loop via a compressed name in dnamepktcopy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-25040?
CVE-2019-25040 is a vulnerability in Unbound before version 1.9.5 that allows an infinite loop via a compressed name in dname_pkt_copy.
Is CVE-2019-25040 a confirmed vulnerability?
The vendor disputes that CVE-2019-25040 is a vulnerability, but it is considered as a vulnerability by security researchers.
Which software is affected by CVE-2019-25040?
Unbound versions before 1.9.5 and Debian Linux version 9.0 are affected by CVE-2019-25040.
How severe is CVE-2019-25040?
CVE-2019-25040 has a severity score of 7.5 (high).
How can I find more information about CVE-2019-25040?
You can find more information about CVE-2019-25040 on the following references: [reference 1], [reference 2], and [reference 3]. Please note that the links provided are for informational purposes only.