Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BIND dnskeygen和dnssec-keygen不安全权限提升漏洞
Vulnerability Description
BIND 8.2.4及其更早版本的dnskeygen,和BIND 9.1.2及其更早版本的dnssec-keygen会为HMAC-MD5设置DNS Transactional Signatures (TSIG)共享密钥文件的不安全权限,攻击者可以获取密钥并执行动态DNS上传。
CVSS Information
N/A
Vulnerability Type
N/A