Input validation error in Knot Resolver - CVE-2019-10191
Published: November 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to hijack domain on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in DNS resolver. A remote attacker can downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.
Affected software
knot-resolver (Alpine package)
knot
knot-resolver (Ubuntu package)
knot-resolver
Fedora
Ubuntu
How to mitigate CVE-2019-10191
knot-resolver (Alpine package) - update to 4.1.0-r0
knot - update to 2.8.2-1.el7
knot-resolver (Ubuntu package) - update to 3.2.1-3ubuntu2.2
knot-resolver - addressed in versions 4.1.0-1.el7, 4.1.0-1.fc29, 4.1.0-1.fc30