CVE-2021-40083

Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
References
Link Resource
https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nic:knot_resolver:*:*:*:*:*:*:*:*

History

30 Aug 2021, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:nic:knot_resolver:*:*:*:*:*:*:*:*
CWE CWE-617
References (MISC) https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169 - (MISC) https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

25 Aug 2021, 02:23

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-25 01:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-40083

Mitre link : CVE-2021-40083

CVE.ORG link : CVE-2021-40083


JSON object : View

Products Affected

nic

  • knot_resolver
CWE
CWE-617

Reachable Assertion