When ldns version 1.7.1 verifies a zone file, the ldnsrrnewfrmstr_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.
{ "urgency": "not yet assigned" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2020-19860.json"