Vulnerability Name: CVE-2007-6283 (CCN-39179) Assigned: 2007-12-13 Published: 2007-12-13 Updated: 2022-02-25 Summary: Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named. CVSS v3 Severity: 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C )3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P )3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-200 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2007-6283 Source: CCN Type: RHSA-2008-0300Moderate: bind security, bug fix, and enhancement update Source: CCN Type: SA28180Fedora BIND "/etc/rndc.key" Insecure File Permissions Source: SECUNIA Type: Third Party Advisory28180 Source: SECUNIA Type: Third Party Advisory30313 Source: REDHAT Type: Vendor AdvisoryRHSA-2008:0300 Source: CCN Type: Red Hat Bugzilla Bug 419421CVE-2007-6283 bind: /etc/rndc.key has 644 permissions by default Source: CONFIRM Type: Issue Tracking, Vendor Advisoryhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-6283 Source: XF Type: UNKNOWNbind-rndc-weak-security(39179) Source: OVAL Type: Third Party Advisoryoval:org.mitre.oval:def:9977 Source: FEDORA Type: Vendor AdvisoryFEDORA-2007-4655 Source: FEDORA Type: Vendor AdvisoryFEDORA-2007-4658 Vulnerable Configuration: Configuration 1 :cpe:/o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:* OR cpe:/o:fedoraproject:fedora_core:*:*:*:*:*:*:*:* Configuration 2 :cpe:/o:oracle:linux:5.0:*:*:*:*:*:*:* Configuration 3 :cpe:/o:centos:centos:5:*:*:*:*:*:*:* Configuration 4 :cpe:/o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_for_ibm_z_systems:5.0_s390x:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_for_power_big_endian:5.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:* Configuration RedHat 1 :cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:* Configuration RedHat 3 :cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:* Configuration RedHat 4 :cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:* Configuration CCN 1 :cpe:/a:isc:bind:*:*:*:*:*:*:*:* AND cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:* Denotes that component is vulnerable Oval Definitions Definition ID Class Title Last Modified oval:org.mitre.oval:def:22620 P ELSA-2008:0300: bind security, bug fix, and enhancement update (Moderate) 2014-05-26 oval:org.mitre.oval:def:9977 V Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named. 2013-04-29 oval:com.redhat.rhsa:def:20080300 P RHSA-2008:0300: bind security, bug fix, and enhancement update (Moderate) 2008-05-21
BACK
redhat enterprise linux 5.0
fedoraproject fedora core *
oracle linux 5.0
centos centos 5
redhat enterprise linux desktop 5.0
redhat enterprise linux for ibm z systems 5.0_s390x
redhat enterprise linux for power big endian 5.0
redhat enterprise linux server 5.0
redhat enterprise linux workstation 5.0
isc bind *
redhat enterprise linux 5
redhat enterprise linux 5
redhat enterprise linux 5