383
VMScore

CVE-2018-10920

Published: 02/08/2018 Updated: 18/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.8 | Impact Score: 4 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Improper input validation bug in DNS resolver component of Knot Resolver prior to 2.4.1 allows remote malicious user to poison cache.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nic knot resolver

Vendor Advisories

Debian Bug report logs - #905325 knot-resolver: CVE-2018-10920: Improper input validation bug in DNS resolver component Package: src:knot-resolver; Maintainer for src:knot-resolver is knot-resolver packagers <knot-resolver@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 3 Aug 2 ...

Github Repositories

Knot Resolver CVE-2018-10920 / DO NOT ABUSE

CVE-2018-10920_PoC Knot Resolver CVE-2018-10920 / DO NOT ABUSE