CNCVE编号:CNCVE-20010497 CVE编号:CAN-2001-0497 安全级别:中 漏洞中文描述: BIND 8.2.4及其早期版本中的dnskeygen,BIND 9.1.2及其早期版本中的dnssec-keygen给DNS Transactional Signatures使用的HMAC-MD5共享的密钥文件设置不安全的许可,这允许攻击者获得密钥并执行动态的DNS。 漏洞英文描述: dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS. 漏洞参考: ISS:20010611 BIND Inadvertent Local Exposure of HMAC-MD5 (TSIG) Keys 系统类型:其他 漏洞类型:设计错误