Description
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
Affected products
- centos / centos5 – 5
- fedoraproject / fedora_core
- oracle / linux5.0 – 5.0
- RedHat / enterprise_linux5.0 – 5.0
- RedHat / enterprise_linux_desktop5.0 – 5.0
- RedHat / enterprise_linux_for_ibm_z_systems5.0_s390x – 5.0_s390x
- RedHat / enterprise_linux_for_power_big_endian5.0 – 5.0
- RedHat / enterprise_linux_server5.0 – 5.0
- RedHat / enterprise_linux_workstation5.0 – 5.0
References
- MISChttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00671.html
- MISChttp://www.redhat.com/support/errata/RHSA-2008-0300.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-6283
- VENDOR_ADVISORYhttp://secunia.com/advisories/28180
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9977
- VENDOR_ADVISORYhttp://secunia.com/advisories/30313
- MISChttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00587.html