CVE-2001-0497: High severity ISC BIND vulnerability
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0497?
CVE-2001-0497 has a high severity due to the potential for unauthorized access to sensitive HMAC-MD5 keys.
How do I fix CVE-2001-0497?
To fix CVE-2001-0497, update BIND to versions later than 8.2.4 and 9.1.2 which secure the permissions of the TSIG key files.
What software is affected by CVE-2001-0497?
CVE-2001-0497 affects BIND versions 8.2.4 and earlier as well as BIND 9.1.2 and earlier.
What is the impact of CVE-2001-0497?
The impact of CVE-2001-0497 allows attackers to obtain HMAC-MD5 shared secret keys enabling unauthorized dynamic DNS updates.
Is there a workaround for CVE-2001-0497?
A workaround for CVE-2001-0497 is to manually adjust the file permissions of the HMAC-MD5 key files to prevent unauthorized access.