PT-2018-5760 · Powerdns · Powerdns Recursor

Published

2018-01-23

·

Updated

2024-06-15

·

CVE-2017-15093

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: PowerDNS Recursor versions 3.x up to and including 3.7.4 PowerDNS Recursor versions 4.x up to and including 4.0.6
Description: The issue allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones when the "api-config-dir" is set to a non-empty value. It was found that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.
Recommendations: For PowerDNS Recursor versions 3.x up to and including 3.7.4, update to a version where the validation of new netmasks and IP addresses of forwarded zones is properly implemented. For PowerDNS Recursor versions 4.x up to and including 4.0.6, update to a version where the validation of new netmasks and IP addresses of forwarded zones is properly implemented. As a temporary workaround, consider restricting access to the API configuration to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15093
OPENSUSE-SU-2024:11157-1

Affected Products

Powerdns Recursor