OSVDB ID: 43907

Title: PowerDNS Administrator Arbitrary Domain Creation

Info

Disclosure

Dec 23, 2007

Discovery

Dec 23, 2007

Dates

Exploit

Dec 23, 2007

Solution

Dec 23, 2007

Description

PowerDNS contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when user attempts to edit domain type. This flaw may lead to a loss of Integrity and/or Availability.

Classification

Location: Local / Remote
Attack Type: Input Manipulation
Impact: Loss of Integrity, Loss of Availability
Solution: Upgrade
Exploit: Exploit Unknown

Solution

Upgrade to version 1.1.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

PowerDns

1.x

References

Credit

  • Samson - samsonBrand New Doo Dooafkmud.com - [None Entered]


Direct URL: http://osvdb.org/36218