CVE-2018-1000002 — Improper Input Validation in Knot Resolver
Severity
3.7LOWNVD
EPSS
0.4%
top 40.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 22
Latest updateMay 13
Description
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-47fr-2fhh-8hrg: Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1↗2022-05-13
OSV▶
CVE-2018-1000002: Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1↗2018-01-22
CVEList▶
CVE-2018-1000002: Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1↗2018-01-22
📋Vendor Advisories
1Debian▶
CVE-2018-1000002: knot-resolver - Improper input validation bugs in DNSSEC validators components in Knot Resolver ...↗2018