CVE-2019-25033

Name
CVE-2019-25033
Description
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/
mailing-list https://lists.debian.org/debian-lts-announce/2021/05/msg00007.html
CONFIRM https://security.netapp.com/advisory/ntap-20210507-0007/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
unbound 3.10-main 1.9.1-r8 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable