First published: Wed Aug 25 2021(Updated: )
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nic Knot Resolver | <5.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40083 is a vulnerability in Knot Resolver before version 5.3.2 that can be triggered by a remote attacker in an edge case.
CVE-2021-40083 has a severity rating of 7.5, which is considered high.
The affected software for CVE-2021-40083 is Knot Resolver before version 5.3.2.
CVE-2021-40083 can be triggered by a remote attacker in an edge case involving NSEC3 with too many iterations used for a positive wildcard proof.
Yes, the fix for CVE-2021-40083 is available in Knot Resolver version 5.3.2.