PT-2018-5760 · Powerdns · Powerdns Recursor
Publicado
2018-01-23
·
Atualizado
2024-06-15
·
CVE-2017-15093
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
PowerDNS Recursor versions 3.x up to and including 3.7.4
PowerDNS Recursor versions 4.x up to and including 4.0.6
Description:
The issue allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones when the "api-config-dir" is set to a non-empty value. It was found that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.
Recommendations:
For PowerDNS Recursor versions 3.x up to and including 3.7.4, update to a version where the validation of new netmasks and IP addresses of forwarded zones is properly implemented.
For PowerDNS Recursor versions 4.x up to and including 4.0.6, update to a version where the validation of new netmasks and IP addresses of forwarded zones is properly implemented.
As a temporary workaround, consider restricting access to the API configuration to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Powerdns Recursor