CVE-2019-25038

Name
CVE-2019-25038
Description
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/
mailing-list https://lists.debian.org/debian-lts-announce/2021/05/msg00007.html
CONFIRM https://security.netapp.com/advisory/ntap-20210507-0007/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
unbound 3.10-main 1.9.1-r8 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable