CVE-2007-6283
Summary
| CVE | CVE-2007-6283 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-18 01:46:00 UTC |
| Updated | 2022-02-25 19:06:00 UTC |
| Description | Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Fedora BIND "/etc/rndc.key" Insecure File Permissions - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| Red Hat update for bind - Secunia Advisories - Vulnerability Intelligence - Secunia.com |
SECUNIA |
secunia.com |
|
| [SECURITY] Fedora 7 Update: bind-9.4.2-2.fc7 |
FEDORA |
www.redhat.com |
|
| 419421 – (CVE-2007-6283) CVE-2007-6283 bind: /etc/rndc.key has 644 permissions by default |
CONFIRM |
bugzilla.redhat.com |
|
| Support |
REDHAT |
www.redhat.com |
|
| [SECURITY] Fedora 8 Update: bind-9.5.0-20.b1.fc8 |
FEDORA |
www.redhat.com |
|
| Repository / Oval Repository |
OVAL |
oval.cisecurity.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2008-05-21 | Mark J Cox | An update to Red Hat Enterprise Linux 5 was released to correct this issue: https://rhn.redhat.com/errata/RHSA-2008-0300.html |
There are currently no legacy QID mappings associated with this CVE.