PT-2019-4362 · Cz.Nic+2 · Knot Resolver+2

·

CVE-2019-10191

·

Published

2019-07-10

·

Updated

2024-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions knot resolver versions prior to 4.1.0
Description A vulnerability was discovered in the DNS resolver of knot resolver, which allows remote attackers to downgrade DNSSEC-secure domains to a DNSSEC-insecure state. This opens the possibility of domain hijack using attacks against the insecure DNS protocol. The issue is due to insufficient input validation, enabling a remote attacker to convert a DNSSEC-secure domain to an insecure state.
Recommendations For versions prior to 4.1.0, update to version 4.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the DNS resolver to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00083
CVE-2019-10191
DLA-3795-1
USN-7047-1

Affected Products

Linuxmint
Ubuntu
Knot Resolver