Unbound before 1.9.5 allows configuration injection in createunboundadservers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. createunboundadservers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libunbound-dev",
            "binary_version": "1.6.7-1ubuntu2.4"
        },
        {
            "binary_name": "libunbound2",
            "binary_version": "1.6.7-1ubuntu2.4"
        },
        {
            "binary_name": "python-unbound",
            "binary_version": "1.6.7-1ubuntu2.4"
        },
        {
            "binary_name": "python3-unbound",
            "binary_version": "1.6.7-1ubuntu2.4"
        },
        {
            "binary_name": "unbound",
            "binary_version": "1.6.7-1ubuntu2.4"
        },
        {
            "binary_name": "unbound-anchor",
            "binary_version": "1.6.7-1ubuntu2.4"
        },
        {
            "binary_name": "unbound-host",
            "binary_version": "1.6.7-1ubuntu2.4"
        }
    ]
}
          {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libunbound-dev",
            "binary_version": "1.9.4-2ubuntu1.2"
        },
        {
            "binary_name": "libunbound8",
            "binary_version": "1.9.4-2ubuntu1.2"
        },
        {
            "binary_name": "python-unbound",
            "binary_version": "1.9.4-2ubuntu1.2"
        },
        {
            "binary_name": "python3-unbound",
            "binary_version": "1.9.4-2ubuntu1.2"
        },
        {
            "binary_name": "unbound",
            "binary_version": "1.9.4-2ubuntu1.2"
        },
        {
            "binary_name": "unbound-anchor",
            "binary_version": "1.9.4-2ubuntu1.2"
        },
        {
            "binary_name": "unbound-host",
            "binary_version": "1.9.4-2ubuntu1.2"
        }
    ]
}