The company OX (Open-Xchange) fixes 5 vulnerabilities for PowerDNS by releasing various patches.
PowerDNS is a mature and very fast open‑source nameserver used by millions of users and companies. It first appeared at the end of the 1990s’ and was acquired in 2015 by the company OX. Its three products are the “Authoritative Server”, “Recursor” and “dnsdist”, which are 100% open source, have 100% support and are used by simple users up to large telecommunications providers.
Of course, in the field of technology and especially computers and Open Source programs, vulnerabilities are often identified. In PowerDNS we find from CVE-2017-15090 to CVE-2017-15094 and they contain DDoS attacks, data processing and more. But let's look at them in a little more detail.
CVE-2017-15090: It concerns PowerDNS Recursor and versions 4.0.0 -4.0.0.6 in which a vulnerability exists in DNSSEC validation if someone uses a man-in-the-middle attack to manipulate data.
CVE- 2017-15091: It is the only one that concerns the PowerDNS Authoritative Server which acquires a security gap if someone has API credentials.
CVE-2017-15092: An XSS (Cross-Site Scripting) vulnerability that allows an attacker to infect the Recursor environment with arbitrary HTML and JavaScript code
CVE-2017-15093: Recursor vulnerability that allows someone to change the program's settings without being authenticated.
CVE-2017-15094: Security vulnerability caused by a memory leak during the analysis and processing of DNSSEC ECDSA keys and causes DdoS attacks.
Η εταιρεία ανέβασε στο site της μια λίστα με τα σφάλματα που έχει και τα αντίστοιχα patches που τα διορθώνουν. Μπορείτε να τα δείτε στο παρακάτω link.
https://doc.powerdns.com/recursor/security-advisories/index.html

