{"id":"CVE-2019-16866","details":"Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.","modified":"2026-09-15T08:16:40.206792Z","published":"2019-10-03T19:15:09.550Z","related":["openSUSE-SU-2024:11005-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"19.04"},{"last_affected":"19.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/Oct/23"},{"type":"ADVISORY","url":"https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4149-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4544"},{"type":"FIX","url":"https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nlnetlabs/unbound","events":[{"introduced":"0"},{"fixed":"240f77ad57e454e493ff6de7938077efe61b3f0d"}],"database_specific":{"cpe":"cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.9.4"}],"source":"CPE_RANGE"}}],"database_specific":{"vanir_signatures_modified":"2026-09-15T08:16:40Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"108668804525512968521245781772799358515","length":1189},"id":"CVE-2019-16866-93becf73","signature_type":"Function","signature_version":"v1","source":"https://github.com/nlnetlabs/unbound/commit/240f77ad57e454e493ff6de7938077efe61b3f0d","target":{"file":"util/data/msgparse.c","function":"parse_edns_from_pkt"}},{"id":"CVE-2019-16866-f09f0838","signature_type":"Line","signature_version":"v1","source":"https://github.com/nlnetlabs/unbound/commit/240f77ad57e454e493ff6de7938077efe61b3f0d","target":{"file":"util/data/msgparse.c"},"deprecated":false,"digest":{"line_hashes":["292524766814039243193904328654959074879","190926310423276515140667372296911008744","27514708243843590347563265495800561936","321487332142836091478680797073649085277","177862212439668206665125480104738939871","304073190949653618221352769714700421182","199722816380111729655073334388716968684","233512743183297187893823043763183726154","76661932854880288768020708891397209453","66006337680159787882268731652111930503","60537033214054800082483590096565279745","238432217213848269294299437068420066889","312452348986823874315585376232563627845","296348926669326276626544425712432599022","74495676082743279379696710893359824232"],"threshold":0.9}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16866.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}