메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15093

관리자 2018.01.25 04:00 조회 수 : 223

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15093
번호 제목 글쓴이 날짜 조회 수
32 CVE-2017-6559 관리자 2017.03.10 100
31 CVE-2017-0104 관리자 2017.03.18 99
30 CVE-2016-3232 관리자 2016.06.17 97
29 CVE-2017-16569 관리자 2017.11.09 96
28 CVE-2017-15039 관리자 2017.11.09 96
27 CVE-2017-16542 관리자 2017.11.09 95
26 CVE-2017-6577 관리자 2017.03.10 95
25 CVE-2017-13134 (imagemagick) 관리자 2017.08.27 94
24 CVE-2017-7402 관리자 2017.04.04 93
23 CVE-2017-12137 관리자 2017.08.27 92
22 CVE-2017-0131 관리자 2017.03.18 92
21 CVE-2017-0119 관리자 2017.03.18 92
20 CVE-2017-0116 관리자 2017.03.18 90
19 CVE-2017-0052 관리자 2017.03.18 89
18 CVE-2017-0065 관리자 2017.03.18 88
위로