메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15093

관리자 2018.01.25 04:00 조회 수 : 225

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15093
번호 제목 글쓴이 날짜 조회 수
557 CVE-2017-0065 관리자 2017.03.18 89
556 CVE-2017-12844 관리자 2017.08.27 89
555 CVE-2017-0052 관리자 2017.03.18 90
554 CVE-2017-0116 관리자 2017.03.18 91
553 CVE-2017-0102 관리자 2017.03.18 92
552 CVE-2017-0119 관리자 2017.03.18 92
551 CVE-2017-0131 관리자 2017.03.18 93
550 CVE-2017-12137 관리자 2017.08.27 93
549 CVE-2017-16542 관리자 2017.11.09 95
548 CVE-2017-6577 관리자 2017.03.10 96
547 CVE-2017-7402 관리자 2017.04.04 96
546 CVE-2016-3232 관리자 2016.06.17 97
545 CVE-2017-15039 관리자 2017.11.09 97
544 CVE-2017-16569 관리자 2017.11.09 97
543 CVE-2017-0104 관리자 2017.03.18 100
위로