Hello Knot DNS users,
CZ.NIC has released Knot DNS 2.5.2 and Knot DNS 2.4.5. Beside several fixes and
improvements,
these versions fix a flaw within the TSIG protocol implementation that would allow an
attacker
with a valid key name and algorithm to bypass the TSIG authentication if no additional
ACL
restrictions is set. This vulnerability was discovered by security experts from
Synacktiv.
Special thanks to them!
Full changelogs:
https://gitlab.labs.nic.cz/labs/knot/raw/v2.5.2/NEWS
https://gitlab.labs.nic.cz/labs/knot/raw/v2.4.5/NEWS
Documentation and migration notes:
https://www.knot-dns.cz/docs/2.5/html/
https://www.knot-dns.cz/docs/2.5/html/migration.html#upgrade-2-4-x-to-2-5-x
Source code:
https://secure.nic.cz/files/knot-dns/knot-2.5.2.tar.xz
https://secure.nic.cz/files/knot-dns/knot-2.5.2.tar.xz.asc
https://secure.nic.cz/files/knot-dns/knot-2.4.5.tar.xz
https://secure.nic.cz/files/knot-dns/knot-2.4.5.tar.xz.asc
Regards,
Daniel