1. CVE-2018-10920/redhat

について、ここに記述してください。

Improper input validation bug in DNS resolver component of knot-resolver before 2.4.1 allows

To execute this attack the attacker has to have: + access to rogue authoritative server and + ability to trigger query from resolver under attack to authoritative server under attacker's control

For successful exploitation the data used to poison cache need to

詳細は当面は公表しない。 

-- ToshinoriMaeno 2018-08-12 00:04:27