PowerDNS patches five security holes in widely used nameserver software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-15094 | An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially cra An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than off or process-no-validate (default). NVD description · AI analysis pending | 5.9 group max | 3% |
| — | ||
| CVE-2017-15091 | An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations t An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY. NVD description · AI analysis pending | 7.1 | 1% |
| — |
Full article308 words · extracted from helpnetsecurity.com · click to collapse
PowerDNS, the company behing the popular open source DNS software of the same name, has pushed out security updates and patches for its Authoritative Server and Recursor offerings that, among other things, fix five security vulnerabilities of note.

“PowerDNS users and customers include leading telecommunications service providers, large scale integrators, Wikipedia, content distribution networks, cable networks / multi service operators and Fortune 500 software companies,” the company proclaims on their site.
“In various important markets, such as Scandinavia, Germany and The Netherlands, PowerDNS is the number one supplier of nameserver software.”
About the vulnerabilities
PowerDNS developer Remi Gacogne detailed the vulnerabilities in a post on the Open Source Security Mailing List (oss-sec), and pointed out each of them can be exploited only if the target has a specific configuration that is not enabled
by default.
The security issues, numbered sequentially CVE-2017-15090 to CVE-2017-15094, can’t lead to system compromise, but can be used to alter the content of records, cause Denial of Service, altering the content of web interfaces, change configurations, and lead to a memory leak.
CVE-2017-15091, they only vulnerability among them that affects the PowerDNS Authoritative server, can be triggered only by attackers who got their hands on valid API credentials.
CVE-2017-15090 can be exploited by attackers who have achieved a man-in-the-middle position to issue a valid signature for bogus DNSSEC records.
CVE-2017-15093 can also only be triggered by attackers with valid API credentials, allowing them to inject new configuration directives into the Recursor’s configuration.
The vulnerabilities have been flagged by Kees Monshouwer, everyman, Chris Navarrete of Fortinet’s Fortiguard Labs, and researchers from cybersecurity company Nixu (during a source code audit).
Risk arising from two of the flaws can be mitigated via workarounds, but implementing the updates (PowerDNS Authoritative 4.0.5 and Recursor 4.0.7) and patches (for the 3.4.11 and 3.7.4 releases) is the preferred solution.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/11/28/powerdns-patches-five-security-holes/