Vulnerabilities
Vulnerable Software
Isc:  >> Bind  >> 9.0.0  Security Vulnerabilities
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
CVSS Score
7.5
EPSS Score
0.094
Published
2006-09-06
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
CVSS Score
7.8
EPSS Score
0.001
Published
2001-07-21


Contact Us

Shodan ® - All rights reserved