CVE-2019-25041: High severity unbound vulnerability
Published Apr 27, 2021
·Updated
DISPUTED Unbound before 1.9.5 allows an assertion failure via a compressed name in dnamepktcopy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited.
Affected Software
2 affected components
nlnetlabs Unbound<1.9.5
Debian Debian Linux=9.0
Remediation
Event History
Apr 27, 2021
CVE Published
via MITRE·05:16 AM
Data Sourced
via MITRE·05:16 AM
Description
Disputed
06:15 AM
Frequently Asked Questions
1
What is CVE-2019-25041?
CVE-2019-25041 is a vulnerability in Unbound DNS before version 1.9.5 that allows an assertion failure via a compressed name in dname_pkt_copy.
2
Is CVE-2019-25041 a confirmed vulnerability?
Yes, CVE-2019-25041 is confirmed as a vulnerability.
3
What is the severity of CVE-2019-25041?
The severity of CVE-2019-25041 is high with a severity value of 7.5.
4
Which software versions are affected by CVE-2019-25041?
Unbound DNS versions before 1.9.5 are affected by CVE-2019-25041.
5
How can I fix CVE-2019-25041?
To fix CVE-2019-25041, upgrade Unbound DNS to version 1.9.5 or later.