CVE-2018-1110: Input Validation
Published Mar 29, 2021
·Updated
A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.
Affected Software
2 affected componentsFixes available
redhat/Knot Resolver<2.3.0
2.3.0
nic Knot Resolver<2.3.0
Event History
Mar 29, 2021
Data Sourced
via Red Hat·06:30 PM
DescriptionSeverityAffected Software
Mar 30, 2021
CVE Published
via MITRE·01:55 AM
Data Sourced
via MITRE·01:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-1110?
CVE-2018-1110 is a vulnerability in knot-resolver before version 2.3.0 that allows malformed DNS messages to cause a denial of service.
2
How does CVE-2018-1110 affect the software?
CVE-2018-1110 affects knot-resolver before version 2.3.0.
3
What is the severity of CVE-2018-1110?
The severity of CVE-2018-1110 is high with a score of 7.5.
4
How do I fix CVE-2018-1110?
To fix CVE-2018-1110, upgrade to version 2.3.0 or higher of knot-resolver.
5
Where can I find more information about CVE-2018-1110?
You can find more information about CVE-2018-1110 at the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=1944328) and [Knot Resolver](https://www.knot-resolver.cz/2018-04-23-knot-resolver-2.3.0.html).