Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15090

Опубликовано: 23 янв. 2018
Источник: debian

Описание

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pdns-recursorfixed4.0.7-1package
pdns-recursorfixed4.0.4-1+deb9u2stretchpackage
pdns-recursornot-affectedjessiepackage
pdns-recursornot-affectedwheezypackage

Примечания

  • https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-03.html

  • Patches: https://downloads.powerdns.com/patches/2017-03/

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 8 лет назад

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.

CVSS3: 5.9
nvd
около 8 лет назад

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.

CVSS3: 5.9
github
больше 3 лет назад

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.

suse-cvrf
около 8 лет назад

Security update for pdns-recursor