Unrated severityNVD Advisory· Published Apr 27, 2021· Updated Aug 5, 2024
CVE-2019-25034
CVE-2019-25034
Description
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Affected products
23- Unbound/Unbounddescription
- osv-coords22 versionspkg:rpm/opensuse/unbound&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/unbound&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/unbound&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/unbound&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/unbound&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/unbound&distro=SUSE%20Manager%20Server%204.1
< 1.6.8-10.6.1+ 21 more
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-3.9.1
- (no CPE)range: < 1.6.8-3.9.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-3.9.1
- (no CPE)range: < 1.6.8-3.9.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
- (no CPE)range: < 1.6.8-10.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.debian.org/debian-lts-announce/2021/05/msg00007.htmlmitremailing-listx_refsource_MLIST
- ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/mitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20210507-0007/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.