VYPR
High severity7.8NVD Advisory· Published Jul 21, 2001· Updated Apr 16, 2026

CVE-2001-0497

CVE-2001-0497

Description

dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.

Affected products

1
  • cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
    Range: <=8.2.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.