CVE-2021-40083

Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
Configurations

Configuration 1 (hide)

cpe:2.3:a:nic:knot_resolver:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:23

Type Values Removed Values Added
References () https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169 - Patch, Third Party Advisory () https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169 - Patch, Third Party Advisory

Information

Published : 2021-08-25 01:15

Updated : 2024-11-21 06:23


NVD link : CVE-2021-40083

Mitre link : CVE-2021-40083

CVE.ORG link : CVE-2021-40083


JSON object : View

Products Affected

nic

  • knot_resolver
CWE
CWE-617

Reachable Assertion