Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-26249

Опубликовано: 21 фев. 2023
Источник: debian
EPSS Низкий

Описание

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
knot-resolverfixed5.6.0-1package
knot-resolverno-dsabullseyepackage
knot-resolverno-dsabusterpackage

Примечания

  • https://www.knot-resolver.cz/2023-01-26-knot-resolver-5.6.0.html

  • https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1380 (v5.6.0)

EPSS

Процентиль: 52%
0.00291
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

CVSS3: 7.5
nvd
почти 3 года назад

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

CVSS3: 7.5
github
почти 3 года назад

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

EPSS

Процентиль: 52%
0.00291
Низкий