CVE-2019-25034
27.04.2021, 06:15
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploitedEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nlnetlabs | unbound | 𝑥 < 1.9.5 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libunbound2 |
| ||||||||||||||||||||||||||||||||||||||||
| libunbound8 |
| ||||||||||||||||||||||||||||||||||||||||
| unbound-anchor |
| ||||||||||||||||||||||||||||||||||||||||
| unbound-devel |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| python3-unbound |
| ||||||||||
| unbound |
| ||||||||||
| unbound-devel |
| ||||||||||
| unbound-libs |
|
References