Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for knot ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1232-1 Rating: moderate References: #1047841 Cross-References: CVE-2017-11104 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for knot fixes the following issues: - CVE-2017-11104: Fixed an improper implementation of TSIG protocol which could have allowed an attacker with a valid key name and algorithm to bypass TSIG authentication (boo#1047841). This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-1232=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): knot-1.6.8-bp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2017-11104.html https://bugzilla.suse.com/1047841 -- . Patch release for openSUSE tackling knot flaw, linked to advisory ID openSUSE-SU-2021:4567-2.. openSUSE Security, knot Update, Authentication Flaw, TSIG Fix, Vulnerability Resolution. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for knot ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1112-1 Rating: moderate References: #1047841 Cross-References: CVE-2017-11104 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for knot fixes the following issues: - CVE-2017-11104: Fixed an improper implementation of TSIG protocol which could have allowed an attacker with a valid key name and algorithm to bypass TSIG authentication (boo#1047841). This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-1112=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): knot-1.6.8-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2017-11104.html https://bugzilla.suse.com/1047841 -- . A recent openSUSE Security Update for dnsmasq resolves a significant vulnerability concerning DNSSEC validation weaknesses.. openSUSE Security Patch, knot Update, Authentication Fix, Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for knot ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1086-1 Rating: moderate References: #1047841 Cross-References: CVE-2017-11104 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for knot fixes the following issues: - CVE-2017-11104: Fixed an improper implementation of TSIG protocol which could have allowed an attacker with a valid key name and algorithm to bypass TSIG authentication (boo#1047841). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1086=1 Package List: - openSUSE Leap 15.2 (x86_64): knot-1.6.8-lp152.5.3.1 knot-debuginfo-1.6.8-lp152.5.3.1 knot-debugsource-1.6.8-lp152.5.3.1 References: https://www.suse.com/security/cve/CVE-2017-11104.html https://bugzilla.suse.com/1047841 -- . Patch for knot resolves a vulnerability allowing authentication bypass in openSUSE Leap 15.2, strengthening system integrity.. openSUSE Security, knot Update, Authentication Bypass, Vulnerability Fix. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for knot ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1085-1 Rating: moderate References: #1047841 Cross-References: CVE-2017-11104 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for knot fixes the following issues: - CVE-2017-11104: Fixed an improper implementation of TSIG protocol which could have allowed an attacker with a valid key name and algorithm to bypass TSIG authentication (boo#1047841). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1085=1 Package List: - openSUSE Leap 15.1 (x86_64): knot-1.6.8-lp151.4.3.1 knot-debuginfo-1.6.8-lp151.4.3.1 knot-debugsource-1.6.8-lp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2017-11104.html https://bugzilla.suse.com/1047841 -- . Patch released for openSUSE addressing knot DNS authentication flaw. Upgrade recommended to maintain secure connectivity.. openSUSE Security Update,knot TSIG authentication fix,moderate security update,knot patch instructions. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for knot ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1395-1 Rating: moderate References: #1047841 Cross-References: CVE-2017-11104 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for knot fixes the following issues: - CVE-2017-11104: Knot DNS contained a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check. (boo#1047841) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-494=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): knot-1.6.5-5.3.1 knot-debuginfo-1.6.5-5.3.1 knot-debugsource-1.6.5-5.3.1 References: https://www.suse.com/security/cve/CVE-2017-11104.html https://bugzilla.suse.com/1047841 -- . This Debian patch resolves a significant vulnerability in bind9, providing improved domain name system safety and reliability.. openSUSE, knot, DNS, security update, TSIG flaw. . LinuxSecurity.com Team
New upstream release: 2.4.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-bd6aa662fc 2017-07-20 13:50:14.517492 --------------------------------------------------------------------------------Name : knot Product : Fedora 24 Version : 2.4.5 Release : 1.fc24 URL : https://www.knot-dns.cz/ Summary : High-performance authoritative DNS server Description : Knot DNS is a high-performance authoritative DNS server implementation. --------------------------------------------------------------------------------Update Information: New upstream release: 2.4.5 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade knot' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New upstream release: 2.4.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d3d38a53f9 2017-07-20 13:51:09.653899 --------------------------------------------------------------------------------Name : knot Product : Fedora 26 Version : 2.4.5 Release : 1.fc26 URL : https://www.knot-dns.cz/ Summary : High-performance authoritative DNS server Description : Knot DNS is a high-performance authoritative DNS server implementation. --------------------------------------------------------------------------------Update Information: New upstream release: 2.4.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #1471118 - CVE-2017-11104 knot: TSIG authentication bypass due to improper TSIG validity period check [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1471118 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade knot' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
new upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5813 2015-04-09 04:56:39 -------------------------------------------------------------------------------- Name : knot Product : Fedora 21 Version : 1.6.3 Release : 1.fc21 URL : https://www.knot-dns.cz/ Summary : An authoritative DNS daemon Description : Knot DNS is a high-performance authoritative DNS server implementation. -------------------------------------------------------------------------------- Update Information: new upstream release -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2015 Jan Vcelak 1.6.3-1 - new upstream release: + fix: performance drop for NSEC-signed zones + fix: proper handling of TCP short-writes + fix: possible out-of-bound reads in zone parser and packet parser + feature: CDS and CDNSKEY support in zone parser + improvement: add defaults for TCP config options into documentation + improvement: detailed error message if zone reload fails * Thu Feb 19 2015 Jan Vcelak 1.6.2-1 - new upstream release: + new config option 'max-tcp-clients' + fix possible resource leak when terminating inactive TCP clients * Tue Jan 20 2015 Jan Vcelak 1.6.1-3 - service file changes: + remove dependency on network.target + remove bounding capabilities (breaks reload) * Sat Dec 13 2014 Jan Vcelak 1.6.1-2 - new upstream release: + DNSSEC: support for Single-Type Signing Scheme + fix: journal file growing over configured limit - service file changes: + run as 'knot' user and group + set security bounding capabilities + change Type to 'notify' * Thu Oct 30 2014 Jan Vcelak 1.6.0-2 - default config: run server as unprivileged user - service file: remove useless startup dependencies - service file: add bounding capabilities -------------------------------------------------------------------------------- This update can be installed with the"yum" update program. Use su -c 'yum update knot' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.