CVE-2017-15093Improper Input Validation in Recursor

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 99.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMay 13

Description

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's config

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

NVDpowerdns/recursor3.03.7.4+1
CVEListV5powerdns/powerdns_recursor3.x up to and including 3.7.4, 4.x up to and including 4.0.6+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jc23-xg6p-84pp: When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 42022-05-13
CVEList
CVE-2017-15093: When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 42018-01-23
OSV
CVE-2017-15093: When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 42018-01-23

📋Vendor Advisories

1
Debian
CVE-2017-15093: pdns-recursor - When api-config-dir is set to a non-empty value, which is not the case by defaul...2017

💬Community

2
Bugzilla
CVE-2017-15090 CVE-2017-15092 CVE-2017-15093 CVE-2017-15094 CVE-2017-15120 pdns-recursor: various flaws [epel-all]2017-12-11
Bugzilla
CVE-2017-15090 CVE-2017-15092 CVE-2017-15093 CVE-2017-15094 pdns-recursor: 4.0.7 release fixing security issues2017-12-11
CVE-2017-15093 — Improper Input Validation in Recursor | cvebase