PT-2018-4979 · Powerdns+1 · Powerdns+3
Mongo
·
Published
2017-01-13
·
Updated
2024-06-15
·
CVE-2016-7073
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PowerDNS versions prior to 3.4.11 and 4.0.2
PowerDNS recursor versions prior to 4.0.4
Description
A problem has been discovered that allows an attacker in a man-in-the-middle position to alter the content of an AXFR due to insufficient validation of TSIG signatures. The issue is caused by a missing check of the TSIG
time and fudge values in AXFRRetriever, which could lead to a replay attack.Recommendations
For PowerDNS versions prior to 3.4.11, update to version 3.4.11 or later.
For PowerDNS versions prior to 4.0.2, update to version 4.0.2 or later.
For PowerDNS recursor versions prior to 4.0.4, update to version 4.0.4 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Powerdns
Powerdns Recursor
Powerdns Authoritative Server