4.3
CVSSv3

CVE-2019-10163

Published: 30/07/2019 Updated: 03/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

A Vulnerability has been found in PowerDNS Authoritative Server prior to 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

powerdns authoritative 4.1.0

powerdns authoritative

opensuse leap 15.0

opensuse leap 15.1

opensuse backports sle-15

Vendor Advisories

Two vulnerabilities have been discovered in pdns, an authoritative DNS server which may result in denial of service via malformed zone records and excessive NOTIFY packets in a master/slave setup For the stable distribution (stretch), these problems have been fixed in version 403-1+deb9u5 We recommend that you upgrade your pdns packages For th ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> PowerDNS Security Advisories 2019-04 and 2019-05 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Erik Winkels &lt ...