CVE-2019-19331 Vulnerability Details

  /     /     /  

CVE-2019-19331 Metadata Quick Info

CVE Published: 16/12/2019 | CVE Updated: 05/08/2024 | CVE Year: 2019
Source: redhat | Vendor: CZ.NIC | Product: knot-resolver
Status : PUBLISHED

CVE-2019-19331 Description

knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-407
CWE Name: CWE-407
Source: CZ.NIC

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).