Knot DNS TSIG Signatures Spoofing Vulnerability
BID:67187
Info
Knot DNS TSIG Signatures Spoofing Vulnerability
| Bugtraq ID: | 67187 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2014 12:00AM |
| Updated: | May 01 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Knot DNS Knot DNS 1.4.4 |
| Not Vulnerable: |
Knot DNS Knot DNS 1.4.5 |
Discussion
Knot DNS TSIG Signatures Spoofing Vulnerability
Knot DNS is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
An attacker can exploit this issue to conduct spoofing attacks. This may aid in further attacks.
Knot DNS prior to 1.4.5 are vulnerable.
Knot DNS is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
An attacker can exploit this issue to conduct spoofing attacks. This may aid in further attacks.
Knot DNS prior to 1.4.5 are vulnerable.
Exploit / POC
Knot DNS TSIG Signatures Spoofing Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Knot DNS TSIG Signatures Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.