Oval Definition:oval:com.ubuntu.cosmic:def:201711104000
Revision Date:2017-07-08Version:1
Title:CVE-2017-11104 on Ubuntu 18.10 (cosmic) - medium.
Description:Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-11104
Platform(s):Ubuntu 18.10
Product(s):
Definition Synopsis
  • Ubuntu 18.10 (cosmic) is installed.
  • AND NOT While related to the CVE in some way, the 'knot' package in cosmic is not affected (note: '2.6.5-3').
  • BACK