Vulnerabilities > CVE-2008-1184 - Credentials Management vulnerability in Dnssec-Tools

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
dnssec-tools
CWE-255
nessus

Summary

The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.

Vulnerable Configurations

Part Description Count
Application
Dnssec-Tools
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2008-1758.NASL
    description1.3.2 release which contains a small set of fixes over the 1.3 release. The biggest of these fixes is a patch to the libval DNSSEC validation library to ensure that the signature that validates it is a signature of the trust anchor itself. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id31171
    published2008-02-26
    reporterThis script is Copyright (C) 2008-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/31171
    titleFedora 7 : dnssec-tools-1.3.2-1.fc7 (2008-1758)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2008-1771.NASL
    description1.3.2 release which contains a small set of fixes over the 1.3 release. The biggest of these fixes is a patch to the libval DNSSEC validation library to ensure that the signature that validates it is a signature of the trust anchor itself. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id31172
    published2008-02-26
    reporterThis script is Copyright (C) 2008-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/31172
    titleFedora 8 : dnssec-tools-1.3.2-1.fc8 (2008-1771)