CVE-2018-1000002: Input Validation
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000002?
CVE-2018-1000002 is a vulnerability that allows an attacker in a man-in-the-middle position to deny the existence of some data in DNS via packet replay in Knot Resolver prior to version 1.5.2.
How severe is CVE-2018-1000002?
CVE-2018-1000002 has a severity rating of medium with a CVSS score of 3.7.
Which software is affected by CVE-2018-1000002?
Knot Resolver prior to version 1.5.2 is affected by CVE-2018-1000002.
How can an attacker exploit CVE-2018-1000002?
An attacker in a man-in-the-middle position can exploit CVE-2018-1000002 by replaying packets and denying the existence of certain data in DNS.
Is there a fix for CVE-2018-1000002?
Yes, the fix for CVE-2018-1000002 is available in Knot Resolver version 1.5.2 and later.