
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25034 affects Unbound versions before 1.9.5, involving an integer overflow vulnerability in the sldns_str2wire_dname_buf_origin function that could lead to an out-of-bounds write. The vulnerability was discovered during a security audit by X41 D-SEC and was publicly disclosed in December 2019. However, the vendor disputes this as a vulnerability, stating that although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited (NVD, OSTIF).
The vulnerability stems from an integer overflow condition in the sldns_str2wire_dname_buf_origin function within sldns/str2wire.c. When dlen + origin_len exceeds sizeof(size_t), the calculation wraps around, resulting in the addition value being smaller than the operands. This could potentially bypass buffer overflow checks and lead to memmove() writing out of bounds. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NetApp).
While the vulnerability could theoretically lead to out-of-bounds write operations which could result in remote code execution, data modification, or denial of service, the vendor disputes the practical exploitability of this issue. According to the vendor's assessment, although the code contains the vulnerability, a running Unbound installation cannot be exploited either remotely or locally (NVD).
The vulnerability was discovered during a security audit rather than being found in the wild. The vendor disputes the practical exploitability of this issue, indicating that while the code may be technically vulnerable, there are no known methods to exploit it in a running Unbound installation (OSTIF).
The issue has been fixed in Unbound version 1.9.5 with commit a3545867fcdec50307c776ce0af28d07046a52dd. Users are recommended to upgrade to this version or later to address the vulnerability (Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."