Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2019-10191

Disclosure Date: July 16, 2019 (last updated April 26, 2024)
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.
Attacker Value
Unknown

CVE-2019-10190

Disclosure Date: July 16, 2019 (last updated April 26, 2024)
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get passed through to the client even if its DNSSEC validation failed, instead of sending a SERVFAIL packet. Caching is not affected by this particular bug but see CVE-2019-10191.
Attacker Value
Unknown

CVE-2018-10920

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.
Attacker Value
Unknown

CVE-2018-1000002

Disclosure Date: January 22, 2018 (last updated November 26, 2024)
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.