CVE-2019-25035 describes an out-of-bounds write vulnerability in Unbound versions prior to 1.9.5, specifically within the sldns_bget_token_par function, affecting Debian and NLnet Labs Unbound distributions. This critical vulnerability (CVSS 9.8) has a low attack complexity and no user interaction required, allowing for potential high impact on confidentiality, integrity, and availability if exploitable. Despite the vendor disputing its exploitability in a running Unbound instance, the high community discussion (10 mentions) suggests significant interest. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.5CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.