iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libunbound-dev", "binary_version": "1.4.22-1ubuntu4.14.04.1" }, { "binary_name": "libunbound2", "binary_version": "1.4.22-1ubuntu4.14.04.1" }, { "binary_name": "python-unbound", "binary_version": "1.4.22-1ubuntu4.14.04.1" }, { "binary_name": "unbound", "binary_version": "1.4.22-1ubuntu4.14.04.1" }, { "binary_name": "unbound-anchor", "binary_version": "1.4.22-1ubuntu4.14.04.1" }, { "binary_name": "unbound-host", "binary_version": "1.4.22-1ubuntu4.14.04.1" } ], "ubuntu_priority": "medium" }