[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-11104 -- knot

ID: oval:org.secpod.oval:def:1901736Date: (C)2019-04-03   (M)2023-12-20
Class: VULNERABILITYFamily: unix




Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
knot
Reference:
CVE-2017-11104
CVE    1
CVE-2017-11104
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:knot:knot
cpe:/o:ubuntu:ubuntu_linux:14.04

© SecPod Technologies