Lucene search

K
redhatcveRedhat.comRH:CVE-2019-25036
HistoryApr 28, 2021 - 7:48 p.m.

CVE-2019-25036

2021-04-2819:48:29
redhat.com
access.redhat.com
18
unbound
assertion triggering
out-of-bounds write
data confidentiality
integrity
service availability

EPSS

0.005

Percentile

76.5%

A flaw was found in unbound. A reachable assertion in the synth_cname function can be triggered by sending invalid packets to the server. If asserts are disabled during compilation, this issue might lead to an out-of-bounds write in dname_pkt_copy function. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.