Authentication bypass in Knot DNS - CVE-2017-11104

 

Authentication bypass in Knot DNS - CVE-2017-11104

Published: July 15, 2017 / Updated: August 24, 2017


Vulnerability identifier: #VU7550
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11104
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to a flaw in the TSIG protocol implementation. A remote attacker can use a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set.

Affected software

Knot DNS
Debian Linux
Fedora
SUSE Linux
Opensuse
knot (Alpine package)
openSUSE Leap
knot

How to mitigate CVE-2017-11104

The vulnerability is addressed in the following versions: 2.4.5 and 2.5.2.

knot - addressed in versions 2.4.5-1.fc26, 2.5.3-2.el7

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins