Oval Definition:oval:com.ubuntu.trusty:def:201711104000
Revision Date:2017-07-08Version:1
Title:CVE-2017-11104 on Ubuntu 14.04 LTS (trusty) - medium.
Description:Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-11104
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND The 'knot' package in trusty is affected and needs fixing.
  • BACK