Unrated severityNVD Advisory· Published Sep 11, 2018· Updated Aug 6, 2024
CVE-2016-7073
CVE-2016-7073
Description
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever, leading to a possible replay attack.
Affected products
2- Open-Xchange/pdnsv5Range: 3.4.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.debian.org/security/2017/dsa-3764mitrevendor-advisoryx_refsource_DEBIAN
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- doc.powerdns.com/md/security/powerdns-advisory-2016-04/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.