메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15093

관리자 2018.01.25 04:00 조회 수 : 38

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15093
번호 제목 글쓴이 날짜 조회 수
467 CVE-2017-7693 관리자 2017.08.27 34
466 CVE-2017-11317 관리자 2017.08.27 34
465 CVE-2017-0057 관리자 2017.03.18 34
464 CVE-2017-15090 관리자 2018.01.25 33
463 CVE-2017-16647 관리자 2017.11.09 33
462 CVE-2017-10793 관리자 2017.09.04 33
461 CVE-2017-14098 관리자 2017.09.04 33
460 CVE-2017-13138 (bridge) 관리자 2017.08.27 33
459 CVE-2017-2741 관리자 2018.01.25 32
458 CVE-2018-5968 관리자 2018.01.25 32
457 CVE-2017-16659 관리자 2017.11.09 32
456 CVE-2017-14099 관리자 2017.09.04 32
455 CVE-2015-1324 관리자 2017.08.27 32
454 CVE-2017-12136 관리자 2017.08.27 32
453 CVE-2017-0005 관리자 2017.03.18 32
위로