dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in...
Moderate severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Feb 8, 2024
Description
Published by the National Vulnerability Database
Jul 21, 2001
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Feb 8, 2024
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
References