CVE-2017-15093: Input Validation
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-15093.
What is the severity of CVE-2017-15093?
The severity of CVE-2017-15093 is medium with a CVSS score of 5.3.
Which software is affected by CVE-2017-15093?
PowerDNS Recursor 3.x up to and including 3.7.4 and 4.x up to and including 4.0.6 are affected by CVE-2017-15093.
What actions can an authorized user perform with CVE-2017-15093?
An authorized user can update the Recursor's ACL by adding and removing netmasks, and configure forward zones.
Are there any references for more information about CVE-2017-15093?
Yes, you can find more information about CVE-2017-15093 at the following links: [1] http://www.securityfocus.com/bid/101982, [2] https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-06.html.