CVE-2017-11104
published 2017-07-08CVE-2017-11104: Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and…
PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
2.68%
84.3th percentile
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | knot | < knot 2.5.3-1 (bookworm) | knot 2.5.3-1 (bookworm) |
| knot-dns | knot_dns | <= 2.4.4 | — |
| knot-dns | knot_dns | — | — |
| knot-dns | knot_dns | — | — |
| knot-dns | knot_dns | >= 0 < 2.5.3-1 | 2.5.3-1 |
| knot-dns | knot_dns | >= 0 < 2.5.3-1 | 2.5.3-1 |
| knot-dns | knot_dns | >= 0 < 2.5.3-1 | 2.5.3-1 |
| knot-dns | knot_dns | >= 0 < 2.5.3-1 | 2.5.3-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xhxv-xr8w-7xpm: Knot DNS before 2
ghsa_unreviewed·2022-05-13
CVE-2017-11104 [MEDIUM] CWE-20 GHSA-xhxv-xr8w-7xpm: Knot DNS before 2
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
OSV
CVE-2017-11104: Knot DNS before 2
osv·2017-07-08·CVSS 5.9
CVE-2017-11104 [MEDIUM] CVE-2017-11104: Knot DNS before 2
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
Debian
CVE-2017-11104: knot - Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG pro...
vendor_debian·2017·CVSS 5.9
CVE-2017-11104 [MEDIUM] CVE-2017-11104: knot - Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG pro...
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
Scope: local
bookworm: resolved (fixed in 2.5.3-1)
bullseye: resolved (fixed in 2.5.3-1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [epel-all]
bugzilla·2017-07-14·CVSS 5.9
CVE-2017-11104 [MEDIUM] CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [epel-all]
CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check
bugzilla·2017-07-14·CVSS 5.9
CVE-2017-11104 [MEDIUM] CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check
CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the
TSIG protocol implementation that would allow an attacker with a valid
key name and algorithm to bypass TSIG authentication if no additional
ACL restrictions are set, because of an improper TSIG validity period
check.
References:
https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.html
Discussion:
Created knot tracking bugs for this issue:
Affects: epel-all [bug 1471119]
Affects: fedora-all [bug 1471118]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those indi
Bugzilla
CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [fedora-all]
bugzilla·2017-07-14·CVSS 5.9
CVE-2017-11104 [MEDIUM] CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [fedora-all]
CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
RFC
Secret Key Transaction Authentication for DNS (TSIG)
rfc·2020-11-01
Secret Key Transaction Authentication for DNS (TSIG)
Internet Engineering Task Force (IETF) F. Dupont
Request for Comments: 8945 ISC
STD: 93 S. Morris
Obsoletes: 2845, 4635 Unaffiliated
Category: Standards Track P. Vixie
ISSN: 2070-1721 Farsight
D. Eastlake 3rd
Futurewei
O. Gudmundsson
Cloudflare
B. Wellington
Akamai
November 2020
Secret Key Transaction Authentication for DNS (TSIG)
Abstract
This document describes a protocol for transaction-level
authentication using shared secrets and one-way hashing. It can be
used to authenticate dynamic updates to a DNS zone as coming from an
approved client or to authenticate responses as coming from an
approved name server.
No recommendation is made here for distributing the shared secrets;
it is expected that a network administrator will statically configure
name servers and clients using so
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00078.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00089.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00049.htmlhttp://www.debian.org/security/2017/dsa-3910http://www.securityfocus.com/bid/99598http://www.synacktiv.ninja/ressources/Knot_DNS_TSIG_Signature_Forgery.pdfhttps://bugs.debian.org/865678https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00078.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00089.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00049.htmlhttp://www.debian.org/security/2017/dsa-3910http://www.securityfocus.com/bid/99598http://www.synacktiv.ninja/ressources/Knot_DNS_TSIG_Signature_Forgery.pdfhttps://bugs.debian.org/865678https://lists.nic.cz/pipermail/knot-dns-users/2017-June/001144.html
2017-07-08
Published