Candidate: CVE-2017-11104 PublicDate: 2017-07-08 10:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11104 https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.html http://www.synacktiv.ninja/ressources/Knot_DNS_TSIG_Signature_Forgery.pdf https://bugs.debian.org/865678 Description: Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=865678 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N [5.9 MEDIUM] Patches_knot: upstream_knot: released (2.5.3-1) precise/esm_knot: DNE trusty_knot: ignored (reached end-of-life) trusty/esm_knot: DNE (trusty was needed) vivid/ubuntu-core_knot: DNE xenial_knot: ignored (end of standard support, was needed) yakkety_knot: ignored (reached end-of-life) zesty_knot: ignored (reached end-of-life) artful_knot: ignored (reached end-of-life) bionic_knot: not-affected (2.6.5-3) cosmic_knot: not-affected (2.6.5-3) disco_knot: not-affected (2.6.5-3) eoan_knot: not-affected (2.6.5-3) focal_knot: not-affected (2.6.5-3) groovy_knot: not-affected (2.6.5-3) hirsute_knot: not-affected (2.6.5-3) impish_knot: not-affected (2.6.5-3) jammy_knot: not-affected (2.6.5-3) devel_knot: not-affected (2.6.5-3)