CVE-2018-1000002Improper Input Validation in Knot Resolver

Severity
3.7LOWNVD
EPSS
0.4%
top 40.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22
Latest updateMay 13

Description

Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages2 packages

NVDnic/knot_resolver< 1.5.2
Debiancz.nic/knot-resolver< 1.5.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-47fr-2fhh-8hrg: Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 12022-05-13
OSV
CVE-2018-1000002: Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 12018-01-22
CVEList
CVE-2018-1000002: Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 12018-01-22

📋Vendor Advisories

1
Debian
CVE-2018-1000002: knot-resolver - Improper input validation bugs in DNSSEC validators components in Knot Resolver ...2018

💬Community

3
Bugzilla
CVE-2018-1000002 knot-resolver: Insufficient DNSSEC validation [fedora-all]2018-01-23
Bugzilla
CVE-2018-1000002 knot-resolver: Insufficient DNSSEC validation [epel-all]2018-01-23
Bugzilla
CVE-2018-1000002 knot-resolver: Insufficient DNSSEC validation2018-01-23
CVE-2018-1000002 — Improper Input Validation | cvebase