PT-2018-4980 · Powerdns+1 · Powerdns+3

Mongo

·

Publicado

2017-01-13

·

Atualizado

2019-10-09

·

CVE-2016-7074

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PowerDNS versions prior to 3.4.11 and 4.0.2 PowerDNS recursor versions prior to 4.0.4
Description The issue allows an attacker in a man-in-the-middle position to alter the content of an AXFR due to insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one leads to the possibility of parsing records that are not covered by the TSIG signature.
Recommendations For PowerDNS versions prior to 3.4.11, update to version 3.4.11 or later. For PowerDNS versions 3.4.11 through 4.0.2, update to version 4.0.2 or later. For PowerDNS recursor versions prior to 4.0.4, update to version 4.0.4 or later. As a temporary workaround, consider implementing additional validation checks for TSIG signatures to prevent alteration of AXFR content.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1425
CVE-2016-7074
DLA-798-1
DSA-3764-1
MGASA-2017-0033

Produtos afetados

Alt Linux
Powerdns
Powerdns Recursor
Powerdns Authoritative Server