메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15093

관리자 2018.01.25 04:00 조회 수 : 223

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15093
번호 제목 글쓴이 날짜 조회 수
467 CVE-2017-0056 관리자 2017.03.18 198
466 CVE-2017-6952 관리자 2017.03.18 198
465 CVE-2018-0845 관리자 2018.01.25 197
464 CVE-2017-14023 관리자 2017.11.09 197
463 CVE-2017-0080 관리자 2017.03.18 197
462 CVE-2017-0059 관리자 2017.03.18 197
461 CVE-2017-16564 관리자 2017.11.09 196
460 CVE-2017-0099 관리자 2017.03.18 196
459 CVE-2017-0005 관리자 2017.03.18 196
458 CVE-2017-6578 (mail-masta) 관리자 2017.03.10 196
457 CVE-2017-6570 관리자 2017.03.10 196
456 CVE-2017-16600 관리자 2018.01.25 195
455 CVE-2017-16603 관리자 2018.01.25 195
454 CVE-2018-5955 관리자 2018.01.25 195
453 CVE-2017-16645 관리자 2017.11.09 195
위로