| Vulnerability Name: | CVE-2019-19331 (CCN-172538) | ||||||||||||||||
| Assigned: | 2019-12-04 | ||||||||||||||||
| Published: | 2019-12-04 | ||||||||||||||||
| Updated: | 2019-12-17 | ||||||||||||||||
| Summary: | knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB). | ||||||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
| Vulnerability Type: | CWE-404 | ||||||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-19331 Source: CONFIRM Type: Exploit, Issue Tracking, Patch https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19331 Source: XF Type: UNKNOWN knot-cve201919331-dos(172538) Source: CCN Type: oss-sec Mailing List, Wed, 4 Dec 2019 17:48:33 +0100 [CVE-2019-19331] Knot Resolver 4.3.0 security release Source: CCN Type: Knot Web site Knot Resolver Source: MISC Type: Release Notes, Vendor Advisory https://www.knot-resolver.cz/2019-12-04-knot-resolver-4.3.0.html | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||