Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25033

Опубликовано: 11 дек. 2019
Источник: redhat
CVSS3: 9.8

Описание

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

A flaw was found in unbound. An integer overflow in the regional allocator via the ALIGN_UP macro may lead to a buffer overflow if the size can be controlled by an attacker. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.

Отчет

There is no available reproducer or proof of concept for this issue, nor it was ever proven the buffer overflow can happen in practice. Indeed this issue was initially considered just as "side-finding", according to the original report, and for this reason its Impact is Moderate. Upstream has also disputed this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundOut of support scope
Red Hat Enterprise Linux 7unboundOut of support scope
Red Hat Enterprise Linux 9unboundNot affected
Red Hat Enterprise Linux 8unboundFixedRHSA-2022:762208.11.2022
Red Hat Enterprise Linux 8.6 Extended Update SupportunboundFixedRHSA-2024:074908.02.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1954775unbound: integer overflow in the regional allocator via the ALIGN_UP macro

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

CVSS3: 9.8
nvd
почти 5 лет назад

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

CVSS3: 9.8
debian
почти 5 лет назад

Unbound before 1.9.5 allows an integer overflow in the regional alloca ...

CVSS3: 9.8
github
больше 3 лет назад

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro.

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость макроса ALIGN_UP DNS-сервера Unbound, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

9.8 Critical

CVSS3