PT-2018-5760 · Powerdns · Powerdns Recursor

Publicado

2018-01-23

·

Atualizado

2024-06-15

·

CVE-2017-15093

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: PowerDNS Recursor versions 3.x up to and including 3.7.4 PowerDNS Recursor versions 4.x up to and including 4.0.6
Description: The issue allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones when the "api-config-dir" is set to a non-empty value. It was found that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.
Recommendations: For PowerDNS Recursor versions 3.x up to and including 3.7.4, update to a version where the validation of new netmasks and IP addresses of forwarded zones is properly implemented. For PowerDNS Recursor versions 4.x up to and including 4.0.6, update to a version where the validation of new netmasks and IP addresses of forwarded zones is properly implemented. As a temporary workaround, consider restricting access to the API configuration to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15093
OPENSUSE-SU-2024:11157-1

Produtos afetados

Powerdns Recursor