Unbound version <= 1.19.3 contains a heap-buffer-overflow vulnerability. The flaw occurs in the cfgmarkports function within the configfile.c file, leading to potential memory corruption. This issue can be triggered when processing certain inputs, causing the application to crash or potentially allowing an attacker to execute arbitrary code.
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
References: http://www.openwall.com/lists/oss-security/2020/05/19/5 https://nlnetlabs.nl/downloads/unbound/CVE-2020-126622020-12663.txt