USN-7047-1
Dashboard / Vulnerabilities / USN-7047-1
USN-7047-1
Summary: knot-resolver vulnerabilities
Details: Vladimír Čunát discovered that Knot Resolver incorrectly handled input during DNSSEC validation. A remote attacker could possibly use this issue to bypass certain validations. (CVE-2019-10190) Vladimír Čunát discovered that Knot Resolver incorrectly handled input during DNSSEC validation. A remote attacker could possibly use this issue to downgrade DNSSEC-secure domains to a DNSSEC-insecure state, resulting in a domain hijacking attack. (CVE-2019-10191) Vladimír Čunát discovered that Knot Resolver incorrectly handled certain DNS replies with many resource records. An attacker could possibly use this issue to consume system resources, resulting in a denial of service. (CVE-2019-19331) Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Knot Resolver incorrectly handled certain queries. A remote attacker could use this issue to perform an amplification attack directed at a target. (CVE-2020-12667)
References: https://ubuntu.com/security/notices/USN-7047-1, https://ubuntu.com/security/CVE-2019-10190, https://ubuntu.com/security/CVE-2019-10191, https://ubuntu.com/security/CVE-2019-19331, https://ubuntu.com/security/CVE-2020-12667
Affected packages
Package
Name: knot-resolver
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
