dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6694 | vdb entry third party advisory |
http://www.osvdb.org/5609 | vdb entry broken link |
http://xforce.iss.net/alerts/advise78.php | third party advisory patch vendor advisory |