Knot-Dns Knot Dns vulnerabilities
2 known vulnerabilities affecting knot-dns/knot_dns.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2016-6171P3HIGHCVSS 8.6fixed in 2.3.02017-02-09
CVE-2016-6171 [HIGH] CWE-400 CVE-2016-6171: Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and
Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.
nvdosv
CVE-2017-11104P4MEDIUMCVSS 5.9≤ 2.4.4v2.5.0+1 more2017-07-08
CVE-2017-11104 [MEDIUM] CWE-20 CVE-2017-11104: Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
nvdosv