Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11104

Опубликовано: 08 июл. 2017
Источник: debian
EPSS Низкий

Описание

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
knotfixed2.5.3-1package

Примечания

  • https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.html

  • http://www.synacktiv.ninja/ressources/Knot_DNS_TSIG_Signature_Forgery.pdf

EPSS

Процентиль: 83%
0.01978
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

CVSS3: 5.9
nvd
больше 8 лет назад

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

suse-cvrf
больше 5 лет назад

Security update for knot

suse-cvrf
больше 5 лет назад

Security update for knot

suse-cvrf
больше 7 лет назад

Security update for knot

EPSS

Процентиль: 83%
0.01978
Низкий