Lucene search

K
cveRedhatCVE-2016-7074
HistorySep 11, 2018 - 1:29 p.m.

CVE-2016-7074

2018-09-1113:29:01
CWE-20
redhat
web.nvd.nist.gov
85
powerdns
vulnerability
content alteration
axfr
tsig signatures
nvd
cve-2016-7074

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

38.0%

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility of parsing records that are not covered by the TSIG signature.

Affected configurations

Nvd
Vulners
Node
powerdnsauthoritativeRange<3.4.11
OR
powerdnsauthoritativeRange4.0.04.0.2
OR
powerdnsrecursorRange<4.0.4
Node
debiandebian_linuxMatch8.0
VendorProductVersionCPE
powerdnsauthoritative*cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
powerdnsrecursor*cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
debiandebian_linux8.0cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "pdns",
    "vendor": "Open-Xchange",
    "versions": [
      {
        "status": "affected",
        "version": "3.4.11"
      },
      {
        "status": "affected",
        "version": "4.0.2"
      },
      {
        "status": "affected",
        "version": "4.0.4"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

38.0%