USN-7047-1: Knot Resolver vulnerabilities
Vladimír Čunát discovered that Knot Resolver incorrectly handled input during DNSSEC validation. A remote attacker could possibly use this issue to bypass certain validations. (CVE-2019-10190) Vladimír Čunát discovered that Knot Resolver incorrectly handled input during DNSSEC validation. A remote attacker could possibly use this issue to downgrade DNSSEC-secure domains to a DNSSEC-insecure state, resulting in a domain hijacking attack. (CVE-2019-10191) Vladimír Čunát discovered that Knot Resolver incorrectly handled certain DNS replies with many resource records. An attacker could possibly use this issue to consume system resources, resulting in a denial of service. (CVE-2019-19331) Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Knot Resolver incorrectly handled certain queries. A remote attacker could use this issue to perform an amplification attack directed at a target. (CVE-2020-12667)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7047-1?
USN-7047-1 is considered a high severity vulnerability due to its potential to allow remote validation bypass in DNSSEC.
How do I fix USN-7047-1?
To fix USN-7047-1, it is recommended to upgrade the Knot Resolver package to version 3.2.1-3ubuntu2.2 or later.
Which systems are affected by USN-7047-1?
USN-7047-1 affects Ubuntu version 20.04 with the Knot Resolver package prior to 3.2.1-3ubuntu2.2.
What vulnerability does USN-7047-1 address?
USN-7047-1 addresses a vulnerability identified by CVE-2019-10190 related to improper input handling during DNSSEC validation.
Who discovered the vulnerability in USN-7047-1?
The vulnerability in USN-7047-1 was discovered by Vladimír Čunát.