Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
References
Configurations
History
No history.
Information
Published : 2020-05-19 13:15
Updated : 2024-11-21 05:00
NVD link : CVE-2020-12667
Mitre link : CVE-2020-12667
CVE.ORG link : CVE-2020-12667
JSON object : View
Products Affected
nic
- knot_resolver
CWE
CWE-400
Uncontrolled Resource Consumption