445
VMScore

CVE-2016-6171

Published: 09/02/2017 Updated: 11/06/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Knot DNS prior to 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

knot-dns knot dns

Vendor Advisories

Debian Bug report logs - #830809 knot: CVE-2016-6171: Improper restriction of zone size limit Package: src:knot; Maintainer for src:knot is knot packagers <knot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Jul 2016 19:00:01 UTC Severity: important Tags: security, upstream ...