#VU9440 File injection in PowerDNS Recursor - CVE-2017-15093
Published: November 29, 2017
PowerDNS Recursor
PowerDNS.COM B.V.
Description
The vulnerability exists in the API of PowerDNS Recursor during a source code audit by Nixu due to insufficient validation of the new netmask and IP addresses of forwarded zones. A remote attacker can add and remove netmasks when api-config-dir is set to a non-empty value and inject new configuration directives into the Recursor’s configuration.