ZeroHour

CVE-2019-19331

PoC
CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description

knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).

Vendors
nicdebian
Products
knot resolver, debian linux
Weakness
CWE-407, CWE-404
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.