CVE-2019-10190

Source
https://cve.org/CVERecord?id=CVE-2019-10190
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10190.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10190
Downstream
Published
2019-07-16T18:15:12.087Z
Modified
2026-02-14T07:34:34.508204Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get passed through to the client even if its DNSSEC validation failed, instead of sending a SERVFAIL packet. Caching is not affected by this particular bug but see CVE-2019-10191.

References

Affected packages

Git / github.com/appneta/tcpreplay

Affected ranges

Type
GIT
Repo
https://github.com/appneta/tcpreplay
Events

Affected versions

v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.5beta1
v4.0.5beta2
v4.0.5beta3
v4.1.0beta1
v4.1.0beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10190.json"

Git / github.com/cz-nic/knot-resolver

Affected ranges

Type
GIT
Repo
https://github.com/cz-nic/knot-resolver
Events

Affected versions

v4.*
v4.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10190.json"