[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-15093 -- pdns-recursor

ID: oval:org.secpod.oval:def:1900810Date: (C)2019-03-05   (M)2023-12-20
Class: VULNERABILITYFamily: unix




When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor"s ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor"s configuration.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
pdns-recursor
Reference:
CVE-2017-15093
CVE    1
CVE-2017-15093
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:powerdns:pdns-recursor
cpe:/o:ubuntu:ubuntu_linux:14.04

© SecPod Technologies