SB2019071608 - Input validation error in Knot Resolver
Published: July 16, 2019 Updated: November 7, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-10191)
The vulnerability allows a remote attacker to hijack domain on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in DNS resolver. A remote attacker can downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.
Remediation
Install update from vendor's website.