Back to search
CVE-2001-0497
Published: Mar 9, 2002
Modified: Aug 8, 2024
PUBLISHED
Description
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
bind-local-key-exposure(6694)
vdb-entry
x_refsource_XF
5609
vdb-entry
x_refsource_OSVDB
20010611 BIND Inadvertent Local Exposure of HMAC-MD5 (TSIG) Keys
third-party-advisory
x_refsource_ISS
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now