CVE-2019-10162 PUBLISHED

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.

EPSS 0.01% · 0.6th percentile

Risk Scores

EPSS Score
0.01%
0.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSpdns0, 3.4.5-1build2, 3.4.6-2
Ubuntu:Pro:18.04:LTSpdns0, 4.0.4-2, 4.0.4-2build1

Timeline

References

Open in Interactive Console →