CVE-2001-0497

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/07/2001
Last modified:
03/04/2025

Description

dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 8.2.4 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.0 (including) 9.1.2 (including)