CVE-2019-10163 PUBLISHED

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

EPSS 0.01% · 0.7th percentile

Risk Scores

EPSS Score
0.01%
0.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSpdns0, 4.0.4-2, 4.0.4-2build1
Ubuntu:Pro:16.04:LTSpdns4.0.0~alpha2-3build1, 0, 4.0.0~alpha2-3ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →