메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15093

관리자 2018.01.25 04:00 조회 수 : 223

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15093
번호 제목 글쓴이 날짜 조회 수
482 CVE-2017-0032 관리자 2017.03.18 161
481 CVE-2017-0030 관리자 2017.03.18 183
480 CVE-2017-0040 관리자 2017.03.18 174
479 CVE-2017-0039 관리자 2017.03.18 105
478 CVE-2017-0035 관리자 2017.03.18 225
477 CVE-2017-0045 관리자 2017.03.18 134
476 CVE-2017-0042 관리자 2017.03.18 134
475 CVE-2017-0043 관리자 2017.03.18 146
474 CVE-2017-0050 관리자 2017.03.18 209
473 CVE-2017-0075 관리자 2017.03.18 146
472 CVE-2017-0074 관리자 2017.03.18 177
471 CVE-2017-0053 관리자 2017.03.18 148
470 CVE-2017-0051 관리자 2017.03.18 167
469 CVE-2017-0052 관리자 2017.03.18 89
468 CVE-2017-0057 관리자 2017.03.18 185
위로